
voidaccess
Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and…

Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and…

Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive

Rail-OT-Protector (ROP) — free, open-source cybersecurity scanning tool for rail and transit OT/SCADA networks. PowerShell + Bash scanners for…

Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats

OMIGOD! OM I GOOD? A free scanner to detect VMs vulnerable to one of the "OMIGOD" vulnerabilities discovered by Wiz's threat research team,…

Minimal proof-of-concept exploit for CVE-2025-49132 in Pterodactyl panels; reads PHP files to extract database credentials and enable unauthorized…

Cortex: a Powerful Observable Analysis and Active Response Engine


Best and simplest tool for website change detection, web page monitoring, and website change alerts. Perfect for tracking content changes, price…

Canary Hunter aims to be a quick PowerShell script to check for Common Canaries in various formats generated for free on canarytokens.org

Find subdomains with GPT, for free

These templates are suggestions of how the Obsidian notetaking tool can be used during an OSINT investigation. The example data in those files should…

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

Concurrent CLI tool for discovering secrets, API keys, and links in JavaScript files during web reconnaissance, with custom regex pattern support and…

Python2.7

CVE-2020-5842 Stored XSS Vulnerability in Codoforum 4.8.3


Qt-based digital signal analyzer, using Suscan core and Sigutils DSP library