


Find vulnerabilities in AD Group Policy, but do it better than Grouper2 did.

Repository contains psexec, which will help to exploit the forgotten pipe

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

An AI-powered tool for discovering privilege escalation opportunities in AWS IAM configurations.

A fast, portable, and lightweight COSE + CBOR implementation for embedded systems. Supports PQC, FIPS 140-3, DO-178, and MISRA C. Powered by wolfSSL.

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container

SpringBoot_Actuator_RCE

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…


The vibe-coding security sentinel. Apache-2.0 agentic security toolkit for AI-assisted projects: 5 deterministic scouts + LLM Brain Layer (BYOK…


Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

WP Full Stripe Free <= 8.4.3 - Missing Authorization

Controlled penetration testing lab demonstrating CVE-2011-2523 exploitation and mitigation techniques.

short view of ruby on rails properties misconfiguration
