
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

A OWASP Based Checklist With 80+ Test Cases

Helps defenders find their WSUS configurations in the wake of CVE-2025-59287

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

A python tool to map the access rights of network shares into a BloodHound OpenGraphs easily

ACEshark is a utility designed for rapid extraction and analysis of Windows service configurations and Access Control Entries, eliminating the need…


Automated Cisco SNMP Enumeration, Brute Force, Configuration Download and Password Cracking

The detection of internal security controls at a company

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

Forked from https://gitlab.alpinelinux.org/kaniini/secfixes-tracker

AWS AMAZON S3 Bucket Takeover Scanner & Claim Tool

Exploit PoC of CVE-2026-6356

Security profiling for blackbox iOS

This project shows the kind of data a rogue iPhone application can collect.


CoWitness is a powerful web application testing tool that enhances the accuracy and efficiency of your testing efforts. It allows you to mimic an…