
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Minimal proof-of-concept exploit for CVE-2025-49132 in Pterodactyl panels; reads PHP files to extract database credentials and enable unauthorized…

The open-source wireless research platform for ESP32.

Forensics artefact collection tool for systems running Microsoft Windows

Rail-OT-Protector (ROP) — free, open-source cybersecurity scanning tool for rail and transit OT/SCADA networks. PowerShell + Bash scanners for…

WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read

Web Based Command Control Framework (C2) #C2 #PostExploitation #CommandControl #RedTeam #C2Framework #PHPC2 #.NETMalware #Malware #PHPMalware #CnC…


NCC Code Navigator

Web Filter External Enumeration Tool (WebFEET)

[No CVE] Apache Solr Arbitrary File Read

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability

Python2.7

SigCorr is the first open-source tool to detect cross-protocol attack chains spanning SS7/MAP, Diameter S6a, and GTPv2-C through unified subscriber…

Sorry, this tool WAS abandoned for a while. I got stress on this thing.

chusa - 注射 - the new generation of sqlmap