

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

chat log tool, easily use your own chat data. 聊天记录工具,轻松使用自己的聊天数据

Local CVE/CPE vulnerability database with search, ranking, web interface, and API for offline vulnerability analysis and management.

Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!

Automated NoSQL database enumeration and web application exploitation tool.

Open-source vulnerability database aggregating CVE data from multiple sources with a web UI and API. Maps vulnerabilities to specific software…

MSDAT: Microsoft SQL Database Attacking Tool


A Python Framework For NoSQL Scanning and Exploitation

Public exploit repository covering local privilege escalation, buffer overflows, and database exploits across Linux, Solaris, AIX, OpenBSD, Zyxel,…

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

Relational database brute force and post exploitation tool for MySQL and MSSQL

Automated tool that hunts for world-readable passwords in Active Directory LDAP databases by leveraging Kerberos authentication and ldapsearch to…

A tool for exploring Firebase datastores.

Tool designed to help identify open Elasticsearch servers that are exposing sensitive information

Hunt Open MongoDB instances