
security-research
Security Research

Security Research

Curated collection of Google dork queries for advanced search engine reconnaissance, uncovering exposed databases, configuration files, admin panels,…

Git All the Payloads! A collection of web attack payloads.


NTLMRawUnhide.py is a Python3 script designed to parse network packet capture files and extract NTLMv2 hashes in a crackable format. The following…

A wordlist framework to fullfill your kinks with your wordlists. For security researchers, bug bounty and hackers.

Wordlist to crack .zip-file password

Python Remote Administration Tool (RAT)

Go-based tool to exploit CVE-2013-4786 for dumping IPMI password hashes via RAKP authentication, supporting concurrent scanning of IP ranges or…

Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.

ZipRarHunter is a powerful command-line ethical hacking tool designed to crack passwords of ZIP and RAR archive files using a wordlist.

A small set of tools to convert packets from capture files to hash files for use with Hashcat or John the Ripper.

Free cross-platform password manager compatible with KeePass

LeakScraper is an efficient set of tools to process and visualize huge text files containing credentials. Theses tools are designed to help…

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

Proof of Concept for the NTLM Hash Leak via .library-ms CVE-2025-24054 / CVE-2025-24071


Crestron AirMedia AM-100 Traversal and Hashdump Metasploit Modules