
Awesome-FOFA
The FOFA Library collects usage tips, common scenarios, F&Q, and more for FOFA.

The FOFA Library collects usage tips, common scenarios, F&Q, and more for FOFA.

Incredibly fast crawler designed for OSINT.

Real-time geospatial OSINT platform aggregating flight, vessel, and satellite data with dark web search, social media dorking, and AI-powered…

A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench,…

Identify privilege escalation paths within and across different clouds

This project explores whether modern OpenSSH reveals valid usernames through subtle response or timing differences. CVE-2016-6210 user enumeration…

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…

Lightweight Python script to test username/password combinations against Zimbra webmail login pages for security assessments and password auditing.

Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

Tests your WAF with +160 payloads

A proof of concept demonstrating how to use the Hinge dating app as a C2.

A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak…

Attack Surface Discovery tool built on a microservice approach, utilizing multi-threading for fast, internet-scale asset indexing

Using IPv6 to Bypass Security

Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

Proof-of-concept exploit for CVE-2023-27350 authentication bypass in PaperCut MF/NG, allowing unauthenticated interaction with vulnerable print…

How to "recover" a CloudPanel server affected by the CVE-2024-44765 vulnerability