
Log4j-CVE-2021-44228
On Thursday (December 9th), a 0-day exploit in the popular Java logging library log4j (version 2) was discovered that results in Remote Code…

On Thursday (December 9th), a 0-day exploit in the popular Java logging library log4j (version 2) was discovered that results in Remote Code…

C# Tool to interact with MS Exchange based on MS docs

EU focused compliance MCP server

vPrioritizer enables us to understand the contextualized risk (vPRisk) on asset-vulnerability relationship level across the organization, for teams…

WordPress pentest tool

[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS

Botnet monitoring is a crucial part in threat analysis and often neglected due to the lack of proper open source tools. Our tool will provide an open…

These templates are suggestions of how the Obsidian notetaking tool can be used during an OSINT investigation. The example data in those files should…

This vulnerability allows an attacker to perform SSRF (Server-Side Request Forgery) attacks on Apache CXF webservices that accept MTOM/XOP requests.…

CVE-2022-46718: an app may be able to read sensitive location information.

CVE-2023-40429: An app may be able to access sensitive user data.

Proof-of-concept for an XXE vulnerability in WorldServer v11.8.2; demonstrates how a crafted .tmx file can leak system files and potentially execute…

Analyzes CVE-2021-42948, a session token exposure vulnerability in HotelDruid, demonstrating how GET parameters leak session IDs and enable session…

YC (S26) | Open Computer History | Record your screen continuously locally and provide context to your agents (Claude, Codex, Openclaw, Hermes,…

Uses ChatGPT API, Bard API, and Llama2, Python-Nmap, DNS Recon, PCAP and JWT recon modules and uses the GPT3 model to create vulnerability reports…


Searching for virtual hosts among non-resolvable domains

Offensive Security recon tool