
Aegis
A free, secure and open source app for Android to manage your 2-step verification tokens.

A free, secure and open source app for Android to manage your 2-step verification tokens.

Curated collection of web attack payloads for XSS, SQLi, command injection, and more. Includes fuzzing lists, password wordlists, and CTF-sourced…

Multi-threaded JWT brute-force cracker in C that recovers secret keys from HS256/HS384/HS512 tokens for security testing. Supports custom alphabet,…

Self-hosted collaborative password manager with AES-256 encryption, LDAP/AD integration, role-based access control, REST API, and Docker deployment…

python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

A friend of SQLmap which will do what you always expected from SQLmap.

Automated tool to deploy Hashtopolis on Google Cloud Shell and Colab for distributed password cracking without dedicated hardware, supporting hashcat…

SolarWinds Orion Account Audit / Password Dumping Utility

High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.

Web-Scale NoSQL Idempotent Cloud-Native Big-Data Serverless Plaintext Credential Search

A cli for cracking, testing vulnerabilities on Json Web Token(JWT)

📜 Scrape targeted wordlists for password cracking using CSS selectors

Curated collection of Google dork queries for advanced search engine reconnaissance, uncovering exposed databases, configuration files, admin panels,…

Python decryption tool for SSCMS CMS encrypted database configurations and user passwords using a hardcoded DES key and IV.

Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original…

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)