
pFuzz
Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security…

PolarDNS is a specialized authoritative DNS server suitable for penetration testing and vulnerability research.

WS-Attacker is a modular framework for web services penetration testing. It is developed by the Chair of Network and Data Security, Ruhr University…

Python-based exploit generator for Adobe Reader BMP/RLE heap corruption (CVE-2013-2729). Demonstrates arbitrary code execution via malicious BMP…


A GUI-based USB device fuzzer

EDID (Enhanced Display Identification Data) Fuzzer

A coverage-guided REST API fuzzer developed on top of LibAFL

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.