
thats_no_pipe
Windows named pipe hooking toolkit

Windows named pipe hooking toolkit

Proof-of-concept reproduction of an nginx heap overflow and info leak (CVE-2026-42533) with two attack surfaces, debug analysis, and a full RCE chain.

Proof-of-concept exploit for CVE-2026-34197, demonstrating authenticated remote code execution in Apache ActiveMQ via Jolokia JMX-HTTP bridge and…

The collaborative web app pentest suite

Kyanos is a networking analysis tool using eBPF. It can visualize the time packets spend in the kernel, capture requests/responses, makes…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Runtime tracer for Node.js malware analysis that hooks core modules, logs calls, spoofs anti-analysis checks, and captures file writes and HTTP…

Proof-of-concept exploit environment for CVE-2026-42945 targeting nginx 1.30.0 on Ubuntu 22.04 with PHP-FPM, packaged as a Docker-based local testing…

Hermes Proxy - HTTP Traffic Analyzer

a dart package to analyze CVE-2025-55182 react2shell

Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures…

Burp Suite extension for automated detection and exploitation of HTTP request smuggling vulnerabilities, supporting HTTP/1.1 and HTTP/2-downgrade…

Adaptive web scraping framework with anti-bot bypass, automatic element relocation, concurrent crawling, proxy rotation, and browser automation for…

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…