
HunterScrape
Python script that uses the hunter.io API to scrape email addresses from a target domain, generating a target list for password spraying attacks.

Python script that uses the hunter.io API to scrape email addresses from a target domain, generating a target list for password spraying attacks.

Uses ChatGPT API, Bard API, and Llama2, Python-Nmap, DNS Recon, PCAP and JWT recon modules and uses the GPT3 model to create vulnerability reports…

Uses Shodan API to pull down C2 servers to run known exploits on them.

Python script that uses Shodan to discover Apache HTTP Server 2.4.49 instances vulnerable to CVE-2021-41773 path traversal and file disclosure.

Python-based directory traversal exploit for CVE-2020-17519 (Apache Flink) with multi-threading, proxy support, and configurable depth for retrieving…

Just a silly recon tool that uses data from SSL Certificates to find potential host names

AttackSurfaceMapper is a tool that aims to automate the reconnaissance process.

Slack enumeration and exposed secrets detection tool

Nuclei-based detection template for CVE-2025-68613, a critical RCE in n8n workflow automation. Uses multi-layered passive fingerprinting to identify…

Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)

Exploit scanner for CVE-2022-26134 in Atlassian Confluence. Uses Shodan to find vulnerable hosts, then executes commands via the OGNL injection…

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

CloudBunny is a tool to capture the real IP of the server that uses a WAF as a proxy or protection. In this tool we used three search engines to…

Proof-of-concept exploit for CVE-2022-40881 targeting SolarView Compact devices. Uses fofa query for reconnaissance and payload delivery for…

Maps nearby Telegram users using trilateration of distance data from the official Telegram library and OpenStreetMap, for OSINT and geolocation…

LinkedIn enumeration tool to extract valid employee names from an organization through search engine scraping

Subdomain and target enumeration tool built for offensive security testing

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…