
dddd
Batch asset collection and vulnerability scanning tool for red teams. Pulls targets from Hunter, Fofa, and Quake, performs fingerprinting, subdomain…

Batch asset collection and vulnerability scanning tool for red teams. Pulls targets from Hunter, Fofa, and Quake, performs fingerprinting, subdomain…

Terminal-first attack surface intelligence engine. Built for speed, portability, and raw technical signal.

Browser-local security monorepo with six modules for mobile APK/IPA triage, client-side DAST fuzzing, OSINT directories, offline AI threat scoring,…

Domain OSINT and security reconnaissance framework running 26 parallel modules for DNS, ports, subdomains, leaked credentials, exposed endpoints,…

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Modern tactical exploitation toolkit.

A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements…

The Outlook HTML Leak Test Project

Python2.7

WordPress HTMega Unauthenticated PII Disclosure Exploit (CVE-2026-4106)


A salty-ass 100% verified hacker status python script to turn apple id's into apple crisp #nicememe

Extraction of iMessage Data via XSS

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.


PoC, Hunting React2Shell about CVE-2025-55182

HTB_Enigma Security Assessment – Full pentest completed, chaining NFS disclosure, IMAPS password reuse, and OS Command Injection in OpenSTAManager…

CVE-2022-26134, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server…