
UPnP-Pentest-Toolkit
UPnP Pentest Toolkit for Windows

UPnP Pentest Toolkit for Windows

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

Facebook account information gathering tool that extracts sensitive personal data (residence, DOB, phone, email) even when target privacy is set to…

Search Google/Bing/Ecosia/DuckDuckGo/Yandex/Yahoo for a search term (dork) with a default set of websites, bug bounty programs or custom collection.

Set of tools to audit SIP based VoIP Systems

PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager


AI agent set for cloud security purple teaming, runs inside Claude Code, Gemini CLI, and Codex.

[First-Blood-XO] React Server Component endpoint vulnerable to CVE-2025-55182 (RCE) → enumerated SUID binaries → /usr/bin/perl had SUID set → used…

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead to sshd to handle some…

Enumerate the permissions associated with AWS credential set

Automated OSINT framework for reconnaissance, data harvesting, and threat intelligence gathering with modular crawlers, scanners, and extraction…

A tool for checking if MFA is enabled on multiple Microsoft Services

Go client to communicate with Chaos DB API.

Subdomain takeover vulnerability checker

HostHunter a recon tool for discovering hostnames using OSINT techniques.

Enumerate information from NTLM authentication enabled web endpoints 🔎