
cloudrasp-log4j2
一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.

一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Hack the World using Termux

Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

Community curated list of templates for the nuclei engine to find security vulnerabilities.

Automatic SQL injection and database takeover tool

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

CVE-2021-31166: exploitation with Powershell, Python, Ruby, NMAP and Metasploit.

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

A single binary that folds a port scanner, the full Exploit-DB index (47k entries) and runnable exploit modules into one tool. Written in Rust, runs…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Popular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulns

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

The Browser Exploitation Framework Project

Multi-engine vulnerability scanner with built-in Nuclei Lite, Afrog, and XRay engines. Features asset discovery via FOFA/Shodan, OOB interaction…

PoC for Webmin Package Update Authenticated Remote Command Execution

CMS渗透测试框架-A CMS Exploit Framework

PAVELOW Exploit Toolbox is a BASH script that corresponds with your KALI distro to better help your vulnerability hunting and exploiting proccess…