
udpx
Single-packet UDP scanner in Go for fast discovery of 45+ services across networks, supporting custom probes, CIDR scanning, and JSONL output.

Single-packet UDP scanner in Go for fast discovery of 45+ services across networks, supporting custom probes, CIDR scanning, and JSONL output.

Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation…

Multi-threaded DNS-based enumeration tool for discovering AWS S3 buckets using pre-compiled wordlists and custom DNS resolvers, with optional Docker…

A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzing

dns rebind tool with custom scripts

Enumerates all websites across an organization's networks via DNS zone transfers and masscan, stores responses, and enables querying for known…

Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…

BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR

Serverless AWS solution for distributing recon and vulnerability scanning workloads. Submit tasks via web UI; EC2 workers execute custom Python…

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

Batch scanning tool for CVE-2019-0708 (BlueKeep) vulnerability detection on Windows systems, supporting single and multi-IP scanning with custom IP…

Blind SQL injection exploit for CVE-2026-49772 targeting The Events Calendar WordPress plugin. Extracts database contents via boolean/time-based…

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets.…

ESXi EZ - A custom scanner that takes list of IPs either in JSON, CSV or individually and checks for infection CVE-2021-21974

Multi‑threaded Python tool to query FOFA API, extract custom fields (IP, port, cert, TLS, etc.), deduplicate results, and resume interrupted searches.

Python-based exploit for CVE-2025-30208 targeting Vite dev server arbitrary file read. Supports single-target detection, custom file paths, system…

Custom exploit written for enumerating usernames as per CVE-2016-6210

Automated exploit for CVE-2024-24919 with API-based vulnerable IP discovery and LFI brute-force using custom wordlists. Designed for educational…