
argus-wp-watcher
WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

Insecure TeamCity CI environment for hands-on penetration testing training: reconnaissance, credential theft, privilege escalation, and lateral…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Web vulnerability scanner written in Python3

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Go client to communicate with Chaos DB API.

A fast WordPress plugin enumeration tool

Tests your WAF with +160 payloads

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

CVE-2026-9830 Proof of Concept

WEB SERVICE SECURITY ASSESSMENT TOOL

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Hidden parameters discovery suite

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

Academic purposes only. Attack against Salesforce lightning with guest privilege.

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…