
Above
Passive network security sniffer that analyzes 28 protocols (ARP, STP, OSPF, VLAN, SCADA) to detect vulnerabilities in network equipment without…

Passive network security sniffer that analyzes 28 protocols (ARP, STP, OSPF, VLAN, SCADA) to detect vulnerabilities in network equipment without…

Fast Python-based subdomain enumeration tool combining passive OSINT and active brute-force scanning with DNS wildcard detection, port scanning, and…

scavenger : is a multi-threaded post-exploitation scanning tool for scavenging systems, finding most frequently used files and folders as well as…

Reverse of OpenAI Privacy Filter: same 1.5B model, returns PII as structured spans instead of masking.

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

UPnP Pentest Toolkit for Windows

High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.

Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

Parses Snaffler output file and generate beautified outputs.

wxpath - declarative web crawling with XPath; a Web Query Language (WQL)


[unmaintained] Post-exploitation tool

PEGASUS-NEO is a comprehensive penetration testing framework designed for security professionals and ethical hackers. It combines multiple security…

PowerSploit - A PowerShell Post-Exploitation Framework

Teamsniper is a tool for fetching keywords in a Microsoft Teams such as (passwords, emails, database, etc.).

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

smbcrawler is no-nonsense tool that takes credentials and a list of hosts and 'crawls' (or 'spiders') through those shares

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)