



Improved SMTP Checker / SMTP Cracker with proxy-support, inbox test and many more features.

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…

FOSSBilling CVE-2026-53647 & CVE-2026-53646 PoC — Unauthenticated API key disclosure & password reset token reuse

Python Hacking Tool for Hackers And Spammers

AI-powered bug bounty hunting toolkit that works with or without subscription.

Web vulnerability scanner written in Python3

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

IPSpinner works as a local proxy that redirects requests through external services.

DEPRECATED, bettercap developement moved here: https://github.com/bettercap/bettercap
