


Local web app for conducting a Check Point Trusted Access Review. This scanner is built specifically to look for configuration issues around…

An AWS CloudFormation template used to provision and manage AWS WAFv2 resources, including a Web ACL, managed rule groups, a custom regex pattern…

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

Hardentools simply reduces the attack surface on Microsoft Windows computers by disabling low-hanging fruit risky features.


JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

Sensitive Data exposure

This tool is used to find php info page

EaseUS MobiMover 6.0.5 Build 21620 - Insecure Files and Folders Permissions

This powershell script is intended to be used by anyone looking to remediate the Log4j Vulnerability within their environment. It can target multiple…

Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574



Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…