
custom-oscp-tooling
OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

A friend of SQLmap which will do what you always expected from SQLmap.


Rid_enum is a null session RID cycle attack for brute forcing domain controllers.

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…

User Enumeration vulnerability in Kaiten (workflow management system)


The SOC Analysts all-in-one CLI tool to automate and speed up workflow.

OSINT tool abusing SecurityTrails domain suggestion API to find potentially related domains by keyword and brute force.

Full penetration testing workflow: credential brute force, SSH access and privilege escalation (CVE-2021-4034)

Modern tactical exploitation toolkit.


Knock Subdomain Scan

Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment

OSINT tool - gets data from services like shodan, censys etc. in one app

DNS Recon | Brute Forcer | DNS Zone Transfer | DNS Wild Card Checks | DNS Wild Card Brute Forcer | Email Enumeration | Staff Enumeration |…

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

A new generation of tool for discovering subdomains( ip , cdn and so on)