
WordList
Curated collection of custom wordlists for fuzzing, DNS enumeration, parameter discovery, and default credentials, plus a Go generator for nuclei…

Curated collection of custom wordlists for fuzzing, DNS enumeration, parameter discovery, and default credentials, plus a Go generator for nuclei…

Manual black-box penetration test of MagnoHost and MeteorCloud infrastructure, documenting exposed MariaDB, default credentials, CVE-2024-27102, and…

Web vulnerability scanner written in Python3

A Ruby library and CLI for generating and working with wordlists.

Alibab-Nacos-Unauthorized-Reset PWD

Burpsuite Plugin For AES Crack


Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR,…

This program Prompts you for the Local File Inclusion information and will automatically search the /etc/passwd and using the users names found will…

PenBox - A Penetration Testing Framework - The Tool With All The Tools , The Hacker's Repo

The Offensive Manual Web Application Penetration Testing Framework.

Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…