
slack-watchman
Slack enumeration and exposed secrets detection tool

Slack enumeration and exposed secrets detection tool

Just a silly recon tool that uses data from SSL Certificates to find potential host names

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…

Nuclei-based detection template for CVE-2025-68613, a critical RCE in n8n workflow automation. Uses multi-layered passive fingerprinting to identify…

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Python-based directory traversal exploit for CVE-2020-17519 (Apache Flink) with multi-threading, proxy support, and configurable depth for retrieving…

LinkedIn enumeration tool to extract valid employee names from an organization through search engine scraping

Uses ChatGPT API, Bard API, and Llama2, Python-Nmap, DNS Recon, PCAP and JWT recon modules and uses the GPT3 model to create vulnerability reports…

Subdomain and target enumeration tool built for offensive security testing

Python script that uses the hunter.io API to scrape email addresses from a target domain, generating a target list for password spraying attacks.

CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

Maps nearby Telegram users using trilateration of distance data from the official Telegram library and OpenStreetMap, for OSINT and geolocation…

AttackSurfaceMapper is a tool that aims to automate the reconnaissance process.

Proof-of-concept exploit for CVE-2022-40881 targeting SolarView Compact devices. Uses fofa query for reconnaissance and payload delivery for…

Exploit scanner for CVE-2022-26134 in Atlassian Confluence. Uses Shodan to find vulnerable hosts, then executes commands via the OGNL injection…

Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)

Python script that uses Shodan to discover Apache HTTP Server 2.4.49 instances vulnerable to CVE-2021-41773 path traversal and file disclosure.

Uses Shodan API to pull down C2 servers to run known exploits on them.