
endext
Extracts all possible endpoints, URLs, and paths from JavaScript files using customizable regex patterns for web application reconnaissance and API…

Extracts all possible endpoints, URLs, and paths from JavaScript files using customizable regex patterns for web application reconnaissance and API…

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

CoWitness is a powerful web application testing tool that enhances the accuracy and efficiency of your testing efforts. It allows you to mimic an…

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

Change monitoring app that checks the content of web pages in different periods.

Six Degrees of Domain Admin

Tests your WAF with +160 payloads

Test target: fresh Laravel 12 app with Livewire pinned to vulnerable 3.6.3 (CVE-2025-54068) for recon scanning

Exploit PoC of CVE-2026-6356

AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security…

Automated Active Directory auditing and enumeration tool that generates detailed HTML audit reports with CSV/XLSX export, designed for security…

HikvisionExploiter - это Python утилита созданная для автоматизации сканирования и проверки прямого доступа к сети камер Hikvision, нацеленная на…

The detection of internal security controls at a company

CVE-2019-1652 /CVE-2019-1653 Exploits For Dumping Cisco RV320 Configurations & Debugging Data AND Remote Root Exploit!

A python tool to map the access rights of network shares into a BloodHound OpenGraphs easily


Controlled virtual attack & defense lab — CVE-2011-2523 exploitation, Nmap recon, Nikto scanning, UFW hardening on Metasploitable 2