
toolbox
Collaborative application security testing between humans and agents via CLI and MCP

Collaborative application security testing between humans and agents via CLI and MCP

An NFC research toolkit application for Android

Penetration test of a Drupal web app — CVE-2018-7600 (Drupalgeddon 2) exploited using Nmap, Burp Suite & Metasploit | Internship @ BB CyberSec

Controlled virtual attack & defense lab — CVE-2011-2523 exploitation, Nmap recon, Nikto scanning, UFW hardening on Metasploitable 2

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Tests your WAF with +160 payloads

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

Walkthroughs for Capture the Flag challenges on the HTB Cybersecurity Platform.

Discover hidden debugging parameters and uncover web application secrets

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)


The Offensive Manual Web Application Penetration Testing Framework.

Bash script that enumerates subdomains via Subfinder, resolves IPs, and identifies live web applications hosted on a domain for reconnaissance and…

A small Php application to fetch archive url snapshots from archive.org. using it you can fetch complete list of snapshot urls of any year or…

Apache Struts 2.0 RCE vulnerability - Allows an attacker to inject OS commands into a web application through the content-type header

application server attack toolkit