
httpx
Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Web technology identification scanner with 1800+ plugins for detecting CMS, servers, JS libraries, and embedded devices. Supports stealthy to…

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through the Remote Debugging…

Proof-of-concept exploit and vulnerability disclosure for HiSilicon hi3520d DVR/NVR devices. Demonstrates RCE via web interface, backdoor…

Wireshark for MCP. A transparent proxy that shows every real tool call between your AI client and your MCP servers, live in your terminal.

NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR,…

A flexible internet crawler used for scanning technologies, instances and vulnerabilities worldwide across the internet.

XSS-based C2 that turns a victim's browser into a proxy for internal scanning, URL fetch, cookie theft, JS execution, and data exfiltration via…

RESTful API wrapping Nmap for automated network scanning, port detection, service enumeration, and vulnerability analysis with optional AI-powered…

Dahua IP camera CVE research toolkit (CVE-2021-33044/33045, CVE-2025-31700/31701)

Self-hosted network discovery and search engine with continuous port scanning, deep protocol probing across ~100 services, local CVE matching, and…

Scans for Telerik UI RCE vulnerability (CVE-2019-18935) via Python and Nmap scripts, supporting IP, hostname, CIDR, and list targets.

Exploit toolkit for CVE-2026-61511 targeting vBulletin pre-auth RCE, featuring multi-endpoint exploitation, WAF bypass via PHPFuck, and…

Weblogic SearchPublicRegistries SSRF(CVE-2014-4210) Exploit Script based on Python3

Java deserialization vulnerability scanner targeting CVE-2017-10271 with nmap integration, multi-target port scanning, and customizable XML-based POC…

Nmap NSE script for detecting and exploiting CVE-2020-5902, a remote code execution vulnerability in F5 BIG-IP traffic management user interface.

mDNS-based AirPlay device discovery tool that scans local networks and tests for CVE-2025-24132 zero-click HTTP RCE vulnerability with a simple GUI…

Multi-VLAN enterprise network vulnerability assessment using Nessus, OWASP ZAP, and Wireshark. Confirms Stored XSS on WebGoat and EternalBlue…