
c2finder
Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

Legion is an open source, easy-to-use, super-extensible and semi-automated network penetration testing tool that aids in discovery, reconnaissance…

Hackable HTTP proxy for resiliency testing and simulated network conditions

An in-memory minimal CPU for agnostic on-the-fly protocols creation

CVE-2020-8554: Man in the middle using LoadBalancer or ExternalIPs

Tools for the IP over HTTPS (IP-HTTPS) Tunneling Protocol

Interactive sip toolkit for packet manipulations, sniffing, man in the middle attacks, fuzzing, simulating of dos attacks.

AI coding agents that can't exfiltrate secrets or merge their own PRs.

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

EPoD (Ethereum Packet of Death)

Proof-of-concept HTTP/2 Bomb exploit for CVE-2026-49975, a cookie-header memory exhaustion DoS in Apache HTTP Server 2.4.17-2.4.67, with Docker lab…

Detection rules for CVE-2026-23918 Apache http2 RCE - Credit: stringa.ai, isec.pl

👻 A LAN dropbox chatbot controllable via Telegram

A MITM (monster-in-the-middle) detection tool. Used to build MALCOLM:

Read-only checker for Citrix NetScaler CTX697096 (CVE-2026-88771–88778): verifies build, CVE preconditions and upgrade risks, and sweeps public IoCs…

Proof-of-concept lab reproducing CVE-2026-19553, where CPython ssl.SSLContext.wrap_bio() silently skips TLS hostname verification when…

Python PoC for CVE-2026-100740, an L2TP Host Name AVP out-of-bounds write in D-Link DIR-895L A1_102b07 tunnel_set_params. Fingerprints the device and…

Mass, multithreaded testing for servers against Heartbleed (CVE-2014-0160).