
prowler
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network

Test and exploit STUN/TURN servers for misconfigurations, enabling internal network pivoting via SOCKS proxy, memory leak attacks, and internal port…

HackBox is a powerful and comprehensive tool that combines a variety of techniques for web application and network security assessments, including…

An ADCS honeypot to catch attackers in your internal network.

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

Offline, read-only hardening check for a self-hosted OpenClaw install — gateway exposure, auth, CVE-2026-25253. Never prints secrets, makes no…

PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials,…

CSRF allows to Add Network Traffic Control Type Rule

Hands-on lab reproducing CVE-2019-11043 PHP-FPM RCE behind nginx, demonstrating reverse-tunnel persistence, memory forensics, and network traffic…

mailcow: Docker Container Exposure to Local Network

CloudMapper helps you analyze your Amazon Web Services (AWS) environments.

Like Envoy xDS, but for eBPF filters

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

[CVE-2021-3019] LanProxy Directory Traversal

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

Shell script to detect and mitigate CVE-2022-2639 in Open vSwitch kernel module. Checks module status, provides remediation steps, and recommends…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…