
AWSBucketDump
Security Tool to Look For Interesting Files in S3 Buckets

Security Tool to Look For Interesting Files in S3 Buckets

uDork is a script written in Bash Scripting that uses advanced Google search techniques to obtain sensitive information in files or directories, find…

A python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those…

A simple Burp Suite extension to crawl JavaScript (JS) files in passive mode and display the results directly on the issues

Proof-of-concept exploit for CVE-2026-37070: an authenticated attacker can read arbitrary uploaded files in Veno File Manager 4.4.9 via a crafted GET…

PoC exploit for CVE-2025-24071, a Windows File Explorer spoofing vulnerability that leaks NTLM hashes via malicious .library-ms files in RAR/ZIP…

DDOS Tool: To take down small websites with HTTP FLOOD. Port scanner: To know the open ports of a site. FTP Password Cracker: To hack file system of…

Bash-based fuzzing tool that leverages Google Dorking for stealthy enumeration of directories, files, subdomains, and parameters without direct…

Recursively searches files for sensitive information using customizable regex patterns, designed for penetration testers to rapidly discover secrets…

Tool to find and extract credentials from phone configuration files hosted on CUCM

Exploit for Grafana LFI vulnerability CVE-2021-43798 enabling unauthorized file reading via path traversal in plugin endpoints.

Proof-of-concept exploit for CVE-2024-36991 enabling arbitrary file read via path traversal in Splunk for Windows versions below 9.2.2, 9.1.5, and…

Exploit code for CVE-2021-33558 targeting Boa/0.94.13 misconfigurations that expose sensitive information via backup, preview, log, and config files.

Pillage filesystems for sensitive information with Go 🔍

Windows link file (shortcuts) examiner

A list of awesome penetration testing tools and resources.

Recursively scan folders with VirusTotal API to detect malware. Features hash lookup, CSV export, real-time progress, and rate-limit handling for…

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading