
hackbox
HackBox is a powerful and comprehensive tool that combines a variety of techniques for web application and network security assessments, including…

HackBox is a powerful and comprehensive tool that combines a variety of techniques for web application and network security assessments, including…

A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.

Security testing tool for analyzing HTTP 403 responses and identifying access control misconfigurations in web applications.

Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and…

Simple Dashboard <= 2.0 - Unauthenticated Privilege Escalation

Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities.


Sorry, this tool WAS abandoned for a while. I got stress on this thing.

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Nuclei Templates Collection

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

This skill helps Claude write secure code and prevent common vulnerabilities.

Content hijacking proof-of-concept using Flash, PDF and Silverlight

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Academic purposes only. Attack against Salesforce lightning with guest privilege.

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…