
ccat
Modular penetration testing tool for cloud container environments. Enumerates ECR repositories, backdoors Docker images, and exploits…

Modular penetration testing tool for cloud container environments. Enumerates ECR repositories, backdoors Docker images, and exploits…

Automating situational awareness for cloud penetration tests.

Docker API CVE-2025-9074 PoC (Proof-Of-Concept). A sophisticated exploitation framework for CVE-2025-9074, targeting unauthenticated Docker API…

a critical memory disclosure vulnerability in MongoDB's zlib compression handling. This tool allows security researchers to extract sensitive data…

Security auditing tool that detects CVE-2025-14847 heap memory leak in MongoDB by sending crafted OP_COMPRESSED messages to leak uninitialized memory…

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

Expose and detail an unauthenticated stored XSS vulnerability in the Google Cloud Vertex AI Python SDK affecting versions 1.98.0 to 1.130.9.

Demonstrates CVE-2026-18953 arbitrary file write in an MCP server's get_resource tool by abusing savePath path traversal; includes vendored…

Multi-CVE exploit tool for Kubernetes ingress-nginx, enabling remote code execution via auth-url, auth-tls-match-cn, and mirror UID injections with…

Penetration testing tool that discovers exposed Docker APIs and grants root-level remote access to containers, with nmap-based scanning and evasion…

Automated Kubernetes penetration testing tool for privilege escalation, service account token theft, secret collection, and cluster pivot attacks…

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

CI/CD pipeline exploitation tool for extracting secrets across Azure DevOps, GitHub, and GitLab by deploying malicious pipelines with automated trace…

A container analysis and exploitation tool for pentesters and engineers.

A tool that implements the Golden SAML attack

Go-based Kubernetes exploitation tool that scans for exposed ports and exploits cluster misconfigurations, including anonymous Kubelet RCE and etcd…

A tool for exploring Firebase datastores.