
SecLists
Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

CredsHunter - Credential Hunting scripts for Windows and Linux OS

Some usefull Scripts and Executables for Pentest & Forensics

Browser-based password cracking toolkit with hash lookup, wordlist generation, rule-based attack simulation, and client-side hash cracking for…

One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

Curated collection of Hashcat password-cracking rules with benchmark data, designed to help red teams and penetration testers crack complex passwords…

Prepostseo Login Checker

PoC for CVE-2025-25198: automated Host header poisoning test for Mailcow - HTTPS listener, automatic cookie/CSRF handling, captures first reset link.

CVE-2025-58434 Proof of Concept


listmonk’s Session Persistence After Password Reset and Password Change

A tool which can be used to generate password list or dictionary from the details of the target


Security Research

Automated remote credential dumper for Windows environments, extracting DPAPI secrets, browser credentials, certificates, and configuration files…

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

Python-based hash cracker supporting SHA512, SHA256, SHA1, MD5, and more. Features auto-detection of hash type, bruteforce, and password list modes…