
TokenTactics
Azure JWT Token Manipulation Toolset

Azure JWT Token Manipulation Toolset

PoC for SpringBreak (CVE-2017-8046)

Python script to detect Sitecore Experience Platform pre-auth RCE (CVE-2021-42237) by probing vulnerable Report.ashx endpoints and analyzing HTTP…

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…

Proof-of-concept exploit for CVE-2026-44578, a Server-Side Request Forgery in Next.js WebSocket upgrade handler. Includes detection mode and…

Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

APK decompiler & secrets scanner for Android security research! Extract leaked API keys, hardcoded credentials, endpoints from APK files. apk2url,…

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

Atlassian Bitbucket Server and Data Center - Command Injection Vulnerability (CVE-2022-36804)

Modular web application reconnaissance framework for automated subdomain enumeration, directory brute-forcing, and extraction of endpoints, JS URLs,…

Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

Reproducer for CVE-2026-47323: Apache Camel CXF/Knative HeaderFilterStrategy missing inbound filtering, enabling Camel control-header injection (RCE…

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

DNS-based subdomain enumeration tool for Azure services, probing App Services, Storage Accounts, Databases, Key Vaults, and CDN endpoints via…

Proof-of-concept exploit for CVE-2026-5029, delivering unauthenticated remote code execution via the run-code MCP tool on exposed HTTP endpoints.…

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Discover hidden debugging parameters and uncover web application secrets

A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzing