
cookiemonster
Decodes and unsigns vulnerable session cookies from Django, Flask, Laravel, Express, and JWT frameworks. Supports HMAC-based decoders, base64…

Decodes and unsigns vulnerable session cookies from Django, Flask, Laravel, Express, and JWT frameworks. Supports HMAC-based decoders, base64…

Exploit Microsoft Zero-Day Vulnerability Follina (CVE-2022-30190)

A lightweight tool for orchestrating and organizing your bug hunting recon / pentesting command-line workflows

GodOfWar - Malicious Java WAR builder with built-in payloads

SSHBuster is a powerful command-line SSH brute-forcing tool designed for ethical hacking and penetration testing. It performs dictionary-based…


CVE-2025-55182 & CVE-2025-66478 Detection Tool for Next.js RSC RCE

Monitor linux processes without root permissions

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Minimal CLI scanner that probes RTP proxies and NAT helpers for NAT-stealing vulnerability, helping VoIP administrators validate and harden media…

A Go-based wrapper for the KNOXSS API to automate XSS vulnerability testing.

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…

Testing TLS/SSL encryption anywhere on any port

A CLI tool for detecting CVE-2023-20048 vulnerability in Cisco Firepower Management Center.

Passive URL discovery tool that collects domain-associated URLs from multiple public sources via command-line, supporting stdin/stdout and JSONL…

BLESuite_CLI is a command line tool to enable an easier way to test Bluetooth Low Energy (BLE) devices

A command line tool to enumerate TLS cipher-suites supported by a server

NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js