
CVE-2017-7529
Proof-of-concept exploit for Nginx integer overflow (CVE-2017-7529) enabling cache header disclosure via crafted range requests, with Docker-based…

Proof-of-concept exploit for Nginx integer overflow (CVE-2017-7529) enabling cache header disclosure via crafted range requests, with Docker-based…

Scans Docker Hub images using regex patterns to extract exposed secrets, private keys, and authentication tokens for security auditing and incident…

A tool to retrieve malware directly from the source for security researchers.

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…


Program to decode radio transmissions from devices on the ISM bands (and other frequencies)

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Automated GraphQL schema enumeration and data extraction tool that iterates introspection documents, reconstructs queries, and saves responses for…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

GraphQL automated security testing toolkit

Scans public code repositories and code snippet platforms to extract and validate AI service API keys with real-time dashboard and multi-format…

Web Application Security Automation Framework which recons the target for various assets to maximize the attack surface for security professionals &…

Tool to identify the best mechanisms for privately disclosing a security vulnerability for a package/project.

Pentester-focused Docker registry tool to enumerate and pull images