
HunterScrape
Python script that uses the hunter.io API to scrape email addresses from a target domain, generating a target list for password spraying attacks.

Python script that uses the hunter.io API to scrape email addresses from a target domain, generating a target list for password spraying attacks.

Uses ChatGPT API, Bard API, and Llama2, Python-Nmap, DNS Recon, PCAP and JWT recon modules and uses the GPT3 model to create vulnerability reports…

Safe Python script to detect Cisco FMC instances potentially vulnerable to CVE-2025-20265. Uses official FMC API to check version, supports…

Python exploit for CVE-2026-89012, a Dolibarr SQL filter denylist bypass that uses a blind-boolean oracle to extract password hashes and API keys via…

Python script that uses Shodan to discover Apache HTTP Server 2.4.49 instances vulnerable to CVE-2021-41773 path traversal and file disclosure.


Python-based directory traversal exploit for CVE-2020-17519 (Apache Flink) with multi-threading, proxy support, and configurable depth for retrieving…

Remote administration service which uses twitter as a command and control server

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

Python exploit for CVE-2024-50395, an authorization bypass in QNAP Media Streaming add-on. Uses crafted User-Agent headers to bypass authentication…

Python exploit for Jenkins CVE-2024-23897: arbitrary file read via CLI args4j parsing, enabling RCE. Scans hosts and extracts sensitive files from…

Just a silly recon tool that uses data from SSL Certificates to find potential host names

CVE querying library and utility that uses a local store syncing directly to the National Vulnerability Database

Python exploit for CVE-2022-36537, an authentication bypass in ZK Framework affecting R1Soft Server Backup Manager, allowing retrieval of web context…

GitLab 12.9.0 Arbitrary File Read

AttackSurfaceMapper is a tool that aims to automate the reconnaissance process.

Slack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace

Hooked browser communication over MQTT