
CLSIDFinder
PowerShell enumeration script for discovering service-backed COM objects via CLSID/AppID correlation and activation testing.

PowerShell enumeration script for discovering service-backed COM objects via CLSID/AppID correlation and activation testing.

Scans WordPress sites for WP Time Capsule plugin CVE-2024-8856, detecting versions below 1.22.22 and logging vulnerable targets to a file.

The Old BloodHound C# Ingestor (Deprecated)

Username Enumeration via Authentication Timing Side-Channel in PaperCut NG

Instagram OSINT tool to export and analyse followers | following with their details

A PoC tool designed to enhance the effectiveness of your traps by spreading breadcrumbs & honeytokens across your systems to lure the attacker toward…

WPScan rewritten in Python + some WPSeku ideas

Login Area Finder: scans host/s for login panels

Nmap scripts to detect exchange 0-day (CVE-2022-41082) vulnerability

a standalone C-based SQL Injection exploit targeting the CVE‑2025‑6907 vulnerability in the CODE_PROJECT service.

Proof‑of‑Concept exploits the Full Path Disclosure bug in the “Birth Chart Compatibility” WordPress plugin (<=v2.0)

【懒人神器】一款图形化、批量采集url、批量对采集的url进行各种nday检测的工具。可用于src挖掘、cnvd挖掘、0day利用、打造自己的武器库等场景。可以批量利用Actively Exploited Atlassian Confluence 0Day…

Domains belonging to the most reputed public bug bounty programs. [NOT FOR NON-MONETARY OR PRIVATE PROGRAMS]

Melody is a transparent internet sensor built for threat intelligence. Supports custom tagging rules and vulnerable application simulation.