
Argus
The Ultimate Information Gathering Toolkit

The Ultimate Information Gathering Toolkit

Forge JWE-wrapped unsigned JWTs to bypass pac4j-jwt signature verification (CVE-2026-29000) and authenticate as any user; includes Python CLI,…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

KASLD derandomizes the Linux kernel's virtual and physical memory layout from a local process, using whatever its vantage — privilege, configuration,…

Stealth Windows process enumeration PoC that lists PIDs using NTFS via NtQueryInformationFile, bypassing standard monitoring APIs and enabling EDR…

Cobalt Strike BOF for live Windows enumeration of open file handles, revealing which process has locked a target file on disk during…

Collection of Brute Ratel C4 BOFs for Windows post-exploitation: process memory access, NetNTLMv2 hash retrieval, contact harvesting, and…

A BOF to enumerate system process, their protection levels, and more.

Rapid Assessment of Web Resources

This repository documents the process of identifying, analyzing, and gathering Open Source Intelligence (OSINT) on a specific security vulnerability…

CoWitness is a powerful web application testing tool that enhances the accuracy and efficiency of your testing efforts. It allows you to mimic an…

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

Python script to scan for CVE-2000-0114 vulnerability in Frontpage Server Extensions. Automates subdomain enumeration and vulnerability scanning…

mass scan for CVE-2025-30208

Script to exploit CVE-2023-38035

This script is intended to automate your reconnaissance process in an organized fashion

CVE-2024-42657 An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the lack of…

In this project, I documented a detailed penetration testing process targeting Apache HTTP Server vulnerabilities, specifically CVE-2021-41773 and…