
petereport
Open-source vulnerability reporting tool for pentesters and security researchers. Manages finding templates, generates reports in HTML, PDF, CSV,…

Open-source vulnerability reporting tool for pentesters and security researchers. Manages finding templates, generates reports in HTML, PDF, CSV,…

A fast DOM based XSS vulnerability scanner with simplicity.

scavenger : is a multi-threaded post-exploitation scanning tool for scavenging systems, finding most frequently used files and folders as well as…

Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but for security…

A penetration testing tool for finding file upload bugs (NDSS 2020)

NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.

Nodesub is a command-line tool for finding subdomains in bug bounty programs

Exploit tool for CVE-2023-27524, an authentication bypass vulnerability in Apache Superset. Enables unauthorized access to vulnerable instances for…

Exploit tool for CVE-2023-27524, an authentication bypass vulnerability in Apache Superset. Enables unauthenticated access to Superset instances for…

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Local file inclusion exploitation tool

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

Disrupt WAF by abusing SSL/TLS Ciphers

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.

A Network Enumeration and Attack Toolset for Windows Active Directory Environments.

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…