
BurpSuite-Grand-Master-Tools
Modular toolkit for pentesters that converts Burp Suite captured HTTP requests into browsable URLs and automates workflow actions with auditable…

Modular toolkit for pentesters that converts Burp Suite captured HTTP requests into browsable URLs and automates workflow actions with auditable…

Passive recon & attack surface mapper — zero requests sent

Turn any web app into an API. Chrome extension captures browser traffic, auto-generates schemas, lets AI replay APIs directly. No official API needed.

Egyscan The Best web vulnerability scanner; it's a multifaceted security powerhouse designed to fortify your web applications against malicious…

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

A salty-ass 100% verified hacker status python script to turn apple id's into apple crisp #nicememe

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…

Automated reconnaissance and XSS detection framework integrating subfinder, httpx, katana, gospider, waybackurls, and dalfox into a 9-stage pipeline…

Apache Struts 2.0 RCE vulnerability - Allows an attacker to inject OS commands into a web application through the content-type header

Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

IFRIT is an AI-powered reverse proxy that intercepts incoming requests in real time, classifying each one as legitimate or malicious. Legitimate…

A detailed walkthrough of Billing room exploiting CVE-2023-30258 and escalating via fail2ban misconfig


Xboard / V2Board Unauth Account Takeover - Magic Link Token Leak (CVE-2026-39912)

PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

