
CVE-2026-94127
Read-only defensive detector for CVE-2026-94127 in F5 BIG-IP APM. Fingerprints hosts, checks versions via iControl REST, and verifies OAuth…

Read-only defensive detector for CVE-2026-94127 in F5 BIG-IP APM. Fingerprints hosts, checks versions via iControl REST, and verifies OAuth…

[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS

Proof-of-concept exploit for CVE-2024-9465, a time-based SQL injection in Check Point Expedition, with Shodan/FOFA search queries and integration…

Exploit for CVE-2026-23980 — Authenticated error-based SQL injection in Apache Superset < 6.0.0 via sqlExpression bypass

Python-based scanner that detects and exploits CVE-2026-24061 telnetd authentication bypass, enabling root shell access on vulnerable GNU Inetutils…

Simple scanner for scanning a list of ip-addresses for vulnerable Ivanti Pulse Secure devices

Scans systems for CVE-2026-31431 (CopyFile vulnerability), enumerates system details, evaluates exposure, reports vulnerable status, and optionally…

Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)

A Python based ingestor for BloodHound

A Python based ingestor for BloodHound

A tool to quickly do keyword searches over Gitlab and Github for OSINT & bug bounty recon

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

PhantomRecon is a CLI-based, modular, agent-driven red team automation tool designed to demonstrate autonomous offensive security workflows powered…

Microsoft Entra ID (Azure AD) Unauthenticated Enumeration

RF CHAOS is an Android App That Is Designed To Cause Chaos via All RF Adapters Possible - Enjoy!

Extracting URLs of a specific target based on the results of "commoncrawl.org"

Fast subdomain enumeration tool written in python.

Firmware and research tools for Nordic Semiconductor nRF24LU1+ based USB dongles and breakout boards.