
toolbox
Collaborative application security testing between humans and agents via CLI and MCP

Collaborative application security testing between humans and agents via CLI and MCP

Penetration test of a Drupal web app — CVE-2018-7600 (Drupalgeddon 2) exploited using Nmap, Burp Suite & Metasploit | Internship @ BB CyberSec

HikvisionExploiter - это Python утилита созданная для автоматизации сканирования и проверки прямого доступа к сети камер Hikvision, нацеленная на…

Safely detect whether a UniFi Network Application controller is vulnerable to CVE-2026-22557

Exploit PoC of CVE-2026-6356

Automated web vulnerability scanner combining URL discovery tools (ParamSpider, waybackurls, gauplus, hakrawler, katana) with Nuclei fuzzing…

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Tests your WAF with +160 payloads

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

A Web Vulnerability Scanner and Patcher

Security tool to find potential vulnerable Server Side Request Forgery (SSRF) parameters.

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

Security research tool for detecting and testing CVE-2025-64446 (FortiWeb Path Traversal RCE vulnerability)

The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The…


tester for cve-2022-31813

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…