
XSStrike
Advanced XSS detection suite with context-aware payload generation, multi-threaded crawling, WAF evasion, and DOM scanning for automated web security…

Advanced XSS detection suite with context-aware payload generation, multi-threaded crawling, WAF evasion, and DOM scanning for automated web security…

The Swiss Army knife for automated Web Application Testing

Reproducer for CVE-2026-49042: demonstrates prompt injection in Apache Camel's langchain4j-tools leading to RCE via unfiltered Exchange headers.…

Perl-based web server scanner that performs comprehensive vulnerability checks, CGI scanning, and server fingerprinting with customizable plugins and…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Web technology identification scanner with 1800+ plugins for detecting CMS, servers, JS libraries, and embedded devices. Supports stealthy to…

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Automatic SSTI detection tool with interactive interface

Semi-automated network penetration testing framework with integrated NMAP, Hydra, Nikto, and CVE-to-exploit mapping for discovery, reconnaissance,…

A fast DOM based XSS vulnerability scanner with simplicity.

CLI tool for automated detection of server-side and client-side template injection vulnerabilities across 44 template engines in 8 programming…

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Multi-architecture Docker toolkit for penetration testing with preconfigured tools for web, network, mobile, API, OSINT, and forensics. Features…

GUI Burp Plugin to ease discovering of security holes in web applications

Windows NT ioctl bruteforcer and modular fuzzer

Exploit for Jenkins serialization vulnerability - CVE-2016-0792