
shannon
Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

A collection of hacking / penetration testing resources to make you better!

A fast WordPress plugin enumeration tool

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

OWASP VBScan is a Black Box vBulletin Vulnerability Scanner

File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

pysap is an open source Python library that provides modules for crafting and sending packets using SAP's NI, Diag, Enqueue, Router, MS, SNC, IGS,…

Academic purposes only. Attack against Salesforce lightning with guest privilege.

burpsuite 的Spring漏洞扫描插件。SpringVulScan:支持检测:路由泄露|CVE-2022-22965|CVE-2022-22963|CVE-2022-22947|CVE-2016-4977

Python PoC validating unauthenticated BookingPress Pro REST API exposure and checking for exposed booking/customer data with configurable request…

phpMyAdmin XSS

POC for Veeam Backup and Replication CVE-2023-27532

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information

CVE-2024-28955 Exploitation PoC