
RPC-Triage
A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

Multi-threaded OSINT web scraper extracting emails, social links, geolocations, and usernames from surface and dark web sources with keyword-based…

🕵️♂️ (2-in-1) Email & Username OSINT suite for deep data extraction just from a single Email/Username. Analyzes 400+ actively maintained scan…

Deep scan domain and find all possible domain to takeover

Unified web reconnaissance toolkit for automated domain intelligence, including subdomain discovery, DNS enumeration, port scanning, SSL inspection,…

Automates BloodHound integration with Cobalt Strike to discover AD escalation paths, mark compromised assets as owned, and investigate beacon…

Multi-source OSINT scanner for email, domain, IP, and organization reconnaissance with SSL vulnerability checks, bitcoin blockchain queries, and…

Modular cybersecurity toolkit for OSINT, forensics, network scanning, and penetration testing with an automation engine, plugin system, and modules…

Metasploit module for CVE-2023-6710 stored XSS exploitation targeting mod_cluster, with PoC and installation guide for ethical penetration testing.

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that…

Open Source Intelligence Interface for Deep Web Scraping

Attack Graph Visualizer and Explorer (Active Directory) ...Who's *really* Domain Admin?

Serverless task distribution framework that parallelizes CLI tools across thousands of cloud functions for rapid reconnaissance and data processing.

An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for…

Easily turn single threaded command line applications into a fast, multi-threaded application with CIDR and glob support.

Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediation.

Crawls web applications to detect second-order subdomain takeover vulnerabilities by collecting URLs and matching configurable rules for non-200…