
OmniSec-Hex
Browser-local security monorepo with six modules for mobile APK/IPA triage, client-side DAST fuzzing, OSINT directories, offline AI threat scoring,…

Browser-local security monorepo with six modules for mobile APK/IPA triage, client-side DAST fuzzing, OSINT directories, offline AI threat scoring,…

Passive DNS server that detects exposed cloud storage buckets (AWS S3, GCP, Azure) by resolving DNS requests, tracing CNAME chains, and flagging…

Non-destructive detection and precondition-verification tool for CVE-2026-58231, probing SAP Commerce Cloud Data Hub endpoints, default OAuth…

Fast and easy-to-use directory brute-forcer written in Go.

SIP Security Assessment Framework for VoIP Pentesters. Presented at DEFCON, BlackHat & Offzone.

Set of tools to audit SIP based VoIP Systems

Read-only Python checker that validates CVE-2026-20079 Cisco FMC authentication-bypass behavior by comparing unauthenticated and csm_processes…

An easy-to-use and lightweight API wrapper for Censys APIs.

Python-based open redirect vulnerability scanner that fuzzes URLs to detect header, JavaScript, and meta tag-based redirects, with integrated…

Fingerprint OpenAI-compatible LLMs from tokenizer and behavior signals.

Proof-of-concept exploit and technical advisory for an unauthenticated member PII disclosure in a WordPress REST API directory plugin, including…

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

Validates and exploits VMware ESXi SFCB authentication bypass (CVE-2021-21994) via a probe/fuzz harness, enabling unauthenticated CIM-XML enumeration.

OWASP Web Recon & Directory Discovery Platform

Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files…


Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

Fast HTTP enumerator