
afrog
A Security Tool for Bug Bounty, Pentest and Red Teaming.

A Security Tool for Bug Bounty, Pentest and Red Teaming.

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

Blind XSS detection and exploitation platform with persistent sessions, reverse proxy, and automated information gathering for penetration testers…

Automated evil twin access point toolkit with traffic capture and real-time monitoring for wireless penetration testing and security research.

Proof-of-concept exploit for CVE-2023-49314 demonstrating code injection in Asana Desktop on macOS via Electron Fuses, with automated vulnerability…

Snipe-IT PoC exploit for CVE-2025-59712 and CVE-2025-59713

macOS dig wrapper that appends spoofed local TXT records to DNS query output, designed to deceive LLM agents into performing automated penetration…

Exploit for CVE-2019-19781 targeting Citrix ADC/NetScaler vulnerability. Provides automated exploitation for penetration testing and red team…

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

C exploit collection for Linux Dirty Pipe (CVE-2022-0847) local privilege escalation, including read-only file overwrite and SUID binary hijacking,…

Automated 802.1x Bypass

This repository contains a Proof-of-Concept (PoC) exploit for the Baron Samedit vulnerability (CVE-2021-3156). The exploit demonstrates privilege…

Automated Attack Simulation in the Cloud, complete with detection use cases.

A scanner and proof-of-concept toolkit for CVE-2026-63030 (wp2shell) - pre-authenticated remote code execution in WordPress core

Automated WPA/WPA2 phishing tool that captures handshakes, spawns a rogue access point, and lures users to a captive portal to harvest credentials…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Automated PoC for CVE-2025-60787 providing authenticated remote code execution against motionEye servers up to 0.43.1b4, with reverse shell and…