
CVE-2025-33073-checker
This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth…

This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth…

A script to enumerate Google Storage buckets, determine what access you have to them, and determine if they can be privilege escalated.

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

CVE-2024-38063 research so you don't have to.


Suite of tools for red teamers and bug hunters to discover ephemeral cloud assets by scanning IP ranges and inspecting SSL certificates for hidden…

Lets Map Your Network enables you to visualise your physical network in form of graph with zero manual error

Instant access to you bug bounty submission dashboard on various platforms + publicly disclosed reports + #bugbountytip

Remote video eavesdropping using a software-defined radio platform


Detection tool for cPanel/WHM CVE-2026-41940 (CRLF injection auth bypass). Verify vulnerability on servers you own or have permission to test. For…

Proof-of-concept exploit for CVE-2024-3400, a command injection in Palo Alto GlobalProtect. Scans targets, triggers RCE, and retrieves configuration…

Scan a Magento site for information

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

CLI scanner for CVE-2006-2842 (PHP include() path truncation) vulnerability. Scans single or multiple URLs to detect this specific web application…

Lightweight CLI scanner for CVE-2021-31589 that checks single or multiple URLs for the vulnerability, outputting results to a file for bug bounty and…

Automated script for Citrix ADC scanner (CVE-2019-19781) using hosts retrieved from Shodan API. You must have a Shodan account to use this script.

Automated script for Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API. You must have a Shodan account to use this…