
forbidden
Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

Scapy: the Python-based interactive packet manipulation program & library.

Hardware tool for RFID analysis, emulation, and penetration testing. Supports 125kHz, 13.56MHz protocols (MIFARE, iClass, ISO14443/15693) with key…

High-speed Burp Suite extension for sending large volumes of HTTP requests with a custom stack, Python-based attack configuration, and advanced…


IEEE 802.11 Wi-Fi testing tool for protocol weakness exploitation, including beacon flooding, deauthentication, packet fuzzing, and IDS evasion.…

poc for CVE-2024-38063 (RCE in tcpip.sys)

A command-line network packet crafting and injection utility

ARM64 ELF Virtual Machine Protection System

Fuzzes CPU implementations by generating test inputs from software proxies, then executes them on real hardware to detect microarchitecture defects…

User-Agent , X-Forwarded-For and Referer SQLI Fuzzer

A Linux framework to enable userspace-defined "Virtual" PCIe card shims to enable in-host PCIe card driver development.

DHCP exhaustion script written in python using scapy network library

Proof of Concept of Sweyntooth Bluetooth Low Energy (BLE) vulnerabilities.


Platform security assessment tool for dumping and analyzing UEFI/SMM registers, PCI config space, physical memory, SPI flash, and S3 bootscripts with…

Real-time GPS signal simulator for bladeRF

This is the full file system fuzzing framework that I presented at the Hack in the Box 2020 Lockdown Edition conference in April.