
Exploits
Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

MAPS cloud scanner and response parser for Microsoft Defender research.

Searches for strings, regex, credit card numbers of magnetic stripe card tracks in a Windows process's memory space

Static Binary Instrumentation tool for Windows x64 executables

MeowEye is a real-time scanner for identifying multiple web vulnerabilities in live applications.

Amazingly fast response crawler to find juicy stuff in the source code! 😎🔥

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

End-to-end exploitation lab for CVE-2025-5548 (FreeFloat FTP Server stack buffer overflow). Includes static analysis with IDA/Ghidra, binary fuzzing,…

Multi-engine vulnerability scanner with built-in Nuclei Lite, Afrog, and XRay engines. Features asset discovery via FOFA/Shodan, OOB interaction…

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

⭐⭐ Join us at SNIA SDC for the SMB3 IO Lab (September 28 - October 1, 2026), see upcoming Interoperability Events

Windows NT ioctl bruteforcer and modular fuzzer

Printer Exploitation Toolkit - The tool that made dumpster diving obsolete.

Detect, analyze and uniquely identify crashes in Windows applications

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

Hardware tool for RFID analysis, emulation, and penetration testing. Supports 125kHz, 13.56MHz protocols (MIFARE, iClass, ISO14443/15693) with key…

A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.

BurpSuite plugin for HTTP packet analysis and fuzzing dictionary generation. Extracts parameters, paths, and files from requests, counts frequency,…