
httpx
Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through the Remote Debugging…

Self-hosted network discovery and search engine with continuous port scanning, deep protocol probing across ~100 services, local CVE matching, and…

Exploit toolkit for CVE-2026-61511 targeting vBulletin pre-auth RCE, featuring multi-endpoint exploitation, WAF bypass via PHPFuck, and…

A flexible internet crawler used for scanning technologies, instances and vulnerabilities worldwide across the internet.

Multi-VLAN enterprise network vulnerability assessment using Nessus, OWASP ZAP, and Wireshark. Confirms Stored XSS on WebGoat and EternalBlue…

Web technology identification scanner with 1800+ plugins for detecting CMS, servers, JS libraries, and embedded devices. Supports stealthy to…

Dahua IP camera CVE research toolkit (CVE-2021-33044/33045, CVE-2025-31700/31701)

NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR,…

Fast network scanner targeting CVE-2025-64459 (Django SQL Injection). Scans IPs, CIDR ranges, custom ports, and paths with configurable concurrency…

A hands-on project demonstrating the setup of virtual security lab, network reconnaissance, and exploitation of CVE-2012-1823.

PoC and NSE scripts for GitLab SSRF (CVE-2023-5612) enabling internal network scanning and validation of webhook URL vulnerabilities.

mDNS-based AirPlay device discovery tool that scans local networks and tests for CVE-2025-24132 zero-click HTTP RCE vulnerability with a simple GUI…

XSS-based C2 that turns a victim's browser into a proxy for internal scanning, URL fetch, cookie theft, JS execution, and data exfiltration via…

RESTful API wrapping Nmap for automated network scanning, port detection, service enumeration, and vulnerability analysis with optional AI-powered…

Rust and Python exploit for CVE-2024-10914, a critical command injection vulnerability in D-Link NAS devices. Sends crafted HTTP requests to execute…

Improved Golang Version of Rapid7 PoC for CVE-2022-1026