
TendaSpill
An exploitation tool to extract passwords using CVE-2015-5995.

An exploitation tool to extract passwords using CVE-2015-5995.

Pentest Tool to generate usernames/logins based on supplied names.

HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.

A python script to extract information from a Microsoft Remote Desktop Web Access (RDWA) application

Brute Force Wordpress Blogs.

Remotely test password strength of WordPress bloging software

Kerberos-based password spraying framework for Active Directory with built-in lockout prevention, user enumeration integration, recursive password…

Lama, the application that does not mache these words.

Detects vulnerable Cisco Meeting Server configurations (CVE-2018-15446) by enumerating active conference IDs and testing weak passcodes for…

Nounours is a tool designed to test APP_KEYs at scale on Laravel applications.

Chiasmodon is an OSINT tool designed to assist in the process of gathering information about a target domain. Its primary functionality revolves…

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

XposedOrNot (XoN) tool is to search an aggregated repository of xposed passwords comprising of ~850 million real time passwords. Usage of such…

Low and slow password spraying tool, designed to spray on an interval over a long period of time

Golang tool designed to exfiltrate passwords found via the sshd and su services

OWASP SAPKiln is a graphical user interface (GUI) tool designed to facilitate securing and auditing SAP systems effectively.

FTPBuster is a powerful command-line brute-forcing tool designed to brute-force FTP, SFTP, and explicit FTPS servers by performing dictionary-based…

ZipRarHunter is a powerful command-line ethical hacking tool designed to crack passwords of ZIP and RAR archive files using a wordlist.