
legion
Legion is an open source, easy-to-use, super-extensible and semi-automated network penetration testing tool that aids in discovery, reconnaissance…

MSDAT: Microsoft SQL Database Attacking Tool

Shodanwave is a tool for exploring and obtaining information from Netwave IP Camera.


Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

A small utility to translate NTDS.dit files to SQLite format.

A fingerprint module, That also adds support of passkeys to linux

CVE-2025-48932 - Unauthenticated SQL injection exploit for Invision Community ≤ 4.7.20. Fully automated exploitation with database enumeration,…

A vulnerability can allow an attacker to guess the automatically generated development mode secret token.

WordPress Simple Link Directory Plugin < 14.8.1 is vulnerable to a high priority Broken Authentication

Set of scripts, to test and exploit the zerologon vulnerability (CVE-2020-1472).

This python file will decrypt the configurationFile used by hikvision cameras vulnerable to CVE-2017-7921.

Arkhota, a web brute forcer for Android.

Remote operations commands implemented using Beacon Object Files

SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.

Windows version of http://sourceforge.net/projects/sshpass/

Writeup of CVE-2020-15906

wpsqli full SQLi extractor + dumper for CVE-2026-60137