
burpflow
BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

Apache Struts 2.0 RCE vulnerability - Allows an attacker to inject OS commands into a web application through the content-type header

Penetration test of a Drupal web app — CVE-2018-7600 (Drupalgeddon 2) exploited using Nmap, Burp Suite & Metasploit | Internship @ BB CyberSec

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Tests your WAF with +160 payloads

Controlled virtual attack & defense lab — CVE-2011-2523 exploitation, Nmap recon, Nikto scanning, UFW hardening on Metasploitable 2

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

Walkthroughs for Capture the Flag challenges on the HTB Cybersecurity Platform.

Collaborative application security testing between humans and agents via CLI and MCP

application server attack toolkit

A small Php application to fetch archive url snapshots from archive.org. using it you can fetch complete list of snapshot urls of any year or…

The Offensive Manual Web Application Penetration Testing Framework.

An NFC research toolkit application for Android

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Bash script that enumerates subdomains via Subfinder, resolves IPs, and identifies live web applications hosted on a domain for reconnaissance and…

Discover hidden debugging parameters and uncover web application secrets
