
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

All-in-One Hacking Tools For Hackers! And more hacking tools! For termux.

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

Inject code and spy on wifi users

An XSS exploitation command-line interface and payload generator.

Self contained htaccess shells and attacks

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

The plugin, used as a companion for the Discy and Himer themes, does not sanitise and escape a parameter on its reset password form which makes it…

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

A lightweight Blind XSS (Cross-Site Scripting) collector and payload server built with Flask

The LAZY script will make your life easier, and of course faster.

Axigen < 10.3.3.47, 10.2.3.12 - Reflected XSS

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

Payload Generation Framework

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

Morpheus - Automating Ettercap TCP/IP (MITM-hijacking Tool)

PhEmail is a python open source phishing email tool that automates the process of sending phishing emails as part of a social engineering test