
wpx
Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…

KisMAC is a free, open source wireless stumbling and security tool for Mac OS X.

A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted…

Terraform-deployable vulnerable-by-design Azure lab with realistic attack paths and common misconfigurations for practicing red teaming and security…

Local testing environment for Next.js middleware authorization bypass vulnerability (CVE-2025-29927). Demonstrates exploitation via crafted…

Repository for CVE-2023-4549 vulnerability.

kernel privilege escalation enumeration and exploitation framework

Secure, Unified, Powerful and Extensible Rust Android Analyzer

一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。

Proof-of-concept exploit for Apple SSL/TLS verification vulnerability (CVE-2014-1266) in iOS and OS X, demonstrating HTTPS interception via a proxy…

iOS 12 / OS X Remote Kernel Heap Overflow (CVE-2018-4407) POC

RootPipe (CVE-2015-1130) and Phoenix (CVE-2015-3673) vulnerability testing utility for Mac OS X 10.2.8 and later

test struts2 vulnerability CVE-2017-5638 in Mac OS X

a PoC for CVE-2024-0379/WP Plugin - Custom Twitter Feeds - A Tweets Widget or X Feed Widget (<= 2.2.1)

Powerview on steroids

Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data