
C2-Pwn
Uses Shodan API to pull down C2 servers to run known exploits on them.

Uses Shodan API to pull down C2 servers to run known exploits on them.

Python client for the WhatCMS.org API to detect 467+ Content Management Systems by domain query, returning name, version, and confidence score for…

Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…

Passive subdomain discovery tool that aggregates results from multiple online sources via CLI, supporting stdin/stdout, JSONL output, and API key…

PowerShell tool for enumerating Azure AD users, devices, applications, and domains via Microsoft Graph API, with offline data export capability.

Know the dangers of credential reuse attacks.

Semantic search over videos using Gemini Embedding 2 or Qwen3-VL.

A simple FOFA client written in JavaFX. Made by WgpSec, Maintained by f1ashine.

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

Script lets you gather malicious software and c&c servers from open source platforms like Malshare, Malcode, Google, Cymon - vxvault, cybercrime…

Simple IP Information Tools for Reputation Data Analysis

Accurately Locate Smartphones using Social Engineering

OSINT tool that scrapes Twitter profile metadata to analyze activity patterns, timezone, language, geolocation, hashtags, and social connections for…

Kubolt utility for scanning public kubernetes clusters

Advanced Recon tool for Bug Bounty and Pentesting

User Enumeration vulnerability in Kaiten (workflow management system)

Test CVE-2018-15473 exploit on Shodan IP