
NoSQLMap
Automated NoSQL database enumeration and web application exploitation tool.

Automated NoSQL database enumeration and web application exploitation tool.

Local CVE/CPE vulnerability database with search, ranking, web interface, and API for offline vulnerability analysis and management.

Open-source vulnerability database aggregating CVE data from multiple sources with a web UI and API. Maps vulnerabilities to specific software…

Practical MSSQL penetration testing cheat sheet covering enumeration, linked-server pivoting, privilege escalation, persistence, and command…

Automated HQL injection exploitation tool for detecting, enumerating tables/columns, and dumping database contents via blind or error-based…

Relational database brute force and post exploitation tool for MySQL and MSSQL

Tool designed to help identify open Elasticsearch servers that are exposing sensitive information

An modular asset discovery framework written in python to automate the repeating manual work

High-speed internet-wide scanner for discovering open MongoDB instances using Masscan and Go-routines, with configurable rate limiting and export of…

Allow exporting the information downloaded with sqlmap to a relational Database like Postgres and sqlite

CVE querying library and utility that uses a local store syncing directly to the National Vulnerability Database

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

Tool to crawl, visualize and interact with SQL server links in a d3 graph to help in your red/blue/purple/.../risk assessments pentest hacking team…

Multi-threaded Windows security scanner that performs port scanning, service banner grabbing, weak password detection, and vulnerability checks…

Blind SQL injection tool for automated database schema enumeration and data extraction. Supports 20+ database engines with evasion techniques for WAF…

Steal Apache Solr instance Queries with or without a username and password.

Curated collection of Google dork queries for advanced search engine reconnaissance, uncovering exposed databases, configuration files, admin panels,…

Python tool for exploiting CVE-2021-35616