


Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…


HopLa Burp Suite Extender plugin - Brings AI capabilities, autocompletion support, and a set of useful payloads to Burp Suite

All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities

A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

A PoC Java Stager which can download, compile, and execute a Java file in memory.

Burp Suite extension to generate Intruder payloads using Radamsa

A more useful CSRF PoC generator on Burp Suite

ZIP File Raider - Burp Extension for ZIP File Payload Testing


NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

Zimbra CVE-2022-27925 PoC