
b374k
PHP Webshell with handy features

PHP Webshell with handy features

Educational Redis rogue server tool for post-exploitation. Deploys a malicious Redis server to achieve remote code execution and execute arbitrary…

Remotely delete access logs, Windows event logs, databases, and files on target machines using automated scanning or manual attack selection for…

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

Proof-of-concept exploit for authenticated remote code execution in PostgreSQL 9.6.1, demonstrating how misconfigured databases can be leveraged for…

Nacos Derby命令执行漏洞利用脚本

POCs to demonstrate CVE-2026-42167 in ProFTPD

Agentless security auditing tool for Linux, macOS, and UNIX systems. Performs in-depth scans for vulnerabilities, configuration issues, and…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

Penetration testing tool for Oracle Databases that discovers valid SIDs, brute-forces credentials, escalates privileges to DBA, executes system…

Advanced MSSQL penetration testing tool for lateral movement, command execution, NTLM relay, and brute-force attacks via linked servers and multiple…

Relational database brute force and post exploitation tool for MySQL and MSSQL

A tool for exploring Firebase datastores.

In-target C# post-exploitation tool for Microsoft SQL Server (MS SQL / MSSQL) traversing linked-server chains of any depth with cascading login…

An anonymizer tool for replacing PII and similar data in dev/test databases copied from production

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.