
solarflare
SolarWinds Orion Account Audit / Password Dumping Utility

SolarWinds Orion Account Audit / Password Dumping Utility

Automated tool that hunts for world-readable passwords in Active Directory LDAP databases by leveraging Kerberos authentication and ldapsearch to…

Windows Oracle Database Attack Toolkit

Penetration testing tool for Oracle Databases that discovers valid SIDs, brute-forces credentials, escalates privileges to DBA, executes system…

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.


CLI tool to scan for and exploit insecure Firebase databases, supporting mass vulnerability scanning, custom JSON payload injection, and URI path…

A new open-source tool to quickly audit SAP permissions.

A tool to crash MySQL servers with CVE-2017-3599

OSINT tool to search, parse and dump only the open Elasticsearch and MongoDB directories that have the data you care about exposing

Strafer: A tool to detect potential infections in Elasticsearch instances

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

Tool to crawl, visualize and interact with SQL server links in a d3 graph to help in your red/blue/purple/.../risk assessments pentest hacking team…

(Deprecated) HQLmap, Automatic tool to exploit HQL injections

Tool designed to help identify open Elasticsearch servers that are exposing sensitive information

Automated testing to find logic and performance bugs in database systems

Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).
