
NINJA-PingU
High-performance network scanner for large-scale IP and port scanning with service identification, embedded device detection, and vulnerability…

High-performance network scanner for large-scale IP and port scanning with service identification, embedded device detection, and vulnerability…

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

In-depth attack surface mapping and asset discovery

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

Next generation web scanner

A burp suite extension that enumerates infrastructure and application admin interfaces (OTG-CONFIG-005)

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

CVE-2024-28955 Exploitation PoC

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

Penetration tests guide based on OWASP including test cases, resources and examples.

OWASP Web Recon & Directory Discovery Platform

A OWASP Based Checklist With 80+ Test Cases

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Remote detection tool for OWASP Core Rule Set version and paranoia level on ModSecurity WAFs, aiding security posture assessment.

A Security Tool for Enumerating WebSockets

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

Advanced HTTP fingerprinting PoC