
subdomain-tko
Detects subdomain takeover vulnerabilities by analyzing DNS records and HTTP responses. Automatically identifies takeover-prone subdomains for…

Detects subdomain takeover vulnerabilities by analyzing DNS records and HTTP responses. Automatically identifies takeover-prone subdomains for…

A flow-based network monitor with Deep Packet Inspection

Zero-day in AppleMediaServices: Bag fetch failure disables Mescal/Absinthe signing. Requests to Apple services proceed unsigned, exposing downgrade,…

Automated man-in-the-middle attack tool.

Proof-of-concept exploit for CVE-2021-33959 demonstrating UDP reflection amplification attack against Plex Media Server via crafted M-SEARCH packets…

Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.

CVE-2025-24813_POC

Reproducer for CVE-2026-48205: Apache Camel camel-dns dns.* header injection redirecting DNS queries to an attacker-controlled resolver (SSRF via…

Knot Resolver CVE-2018-10920 / DO NOT ABUSE


Proof-of-concept exploit for CVE-2025-32407: TLS certificate validation bypass in Samsung Internet for Galaxy Watch, enabling Man-in-the-Middle…

Proof-of-concept exploit for CVE-2020-1350, a critical remote code execution vulnerability in Windows DNS Server. Demonstrates exploitation via…


CVE-2023-1671-POC, based on dnslog platform

Proof-of-concept exploit for CVE-2023-52235 demonstrating DNS rebinding attack against SpaceX Starlink user terminals to bypass network security…

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

Woeful is a tool that lets web apps to safely and securely connect to the outside internet without a complex backend.