
djangohunter
Tool designed to help identify incorrectly configured Django applications that are exposing sensitive information.

Tool designed to help identify incorrectly configured Django applications that are exposing sensitive information.

Now, the Host is Mine! - Super Fast Sub-domain Takeover Detection!

SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.

Enemies Of Symfony - Debug mode Symfony looter

A New Approach to Directory Bruteforce with WaybackLister v1.0

Kubolt utility for scanning public kubernetes clusters

Academic purposes only. Attack against Salesforce lightning with guest privilege.

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

A small python script to check for Cross-Site Tracing (XST)

EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify…

Multithreaded Plugin based vulnerability scanner for mass detection of web-based applications vulnerabilities

Fingerprints servers, finds exploits, scans WebDAV. May or may not also make coffee.

Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…

🦁 Python project to identify and scan for vulnerabilities related to the Joomla CMS project. It scans for common misconfigurations and public…

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

Curated SIEM queries and techniques for offensive discovery of Windows privilege escalation, misconfigured ACLs, services, scheduled tasks, and…

Adobe Experience Manager (AEM) hacking toolkit