
Argus
Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

Secure, modular MCP server wrapping nmap, nuclei, gobuster, subfinder, httpx, nikto, sqlmap for AI-powered pentesting

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

PhantomRecon is a CLI-based, modular, agent-driven red team automation tool designed to demonstrate autonomous offensive security workflows powered…

针对类似CVE-2017-10271漏洞的一个java反序列化漏洞扫描器

IPv6 analysis tool: the other side

A tool to perform port scanning using vulnerable Request-Baskets

CVE-2014-4210 SSRF PORTSCANNER PoC


Proof of Concept exploit for Server Side Request Forgery vulnerability in Requests Basket v1.2.1 and before.

CVE-2025-64459-hunter

Weblogic SearchPublicRegistries SSRF(CVE-2014-4210) Exploit Script based on Python3

PoC and internal port brute-forcer for CVE-2023-27163


Efficient and advanced man in the middle framework

NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR,…