


Scan for misconfigured S3 buckets across S3-compatible APIs!

Privilege Escalation Project - Windows / Linux / Mac

A simple CORS misconfiguration scanner


Check UNIX/Linux systems for privilege escalation

Automated CORS misconfiguration scanner that tests Origin header injection, wildcard reflection, and credential leakage across web applications and…

Public OCI-Image (docker image) Security Checker

Prommetrix can obtain relevant information from the instances of 'Node Exporter' executed by 'Prometheus'.

Tool designed to help identify incorrectly configured Django applications that are exposing sensitive information.

A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific…

A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting)…

gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

🦁 Python project to identify and scan for vulnerabilities related to the Joomla CMS project. It scans for common misconfigurations and public…

Bucky (An automatic S3 bucket discovery tool)

Detect and fix log4j log4shell vulnerability (CVE-2021-44228)