


Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Ultimate Internet of Things/Industrial Control Systems reconnaissance tool.

Python scripts for security assessment of industrial PLCs: scanning, enumeration, control, and exploitation of Beckhoff, Siemens, Schneider,…

Real world and CTFs exploiting web/binary POCs.

BOF (Boiboite Opener Framework) is a testing framework for industrial protocols implementations and devices.

PoC C&C for the Industroyer malware


ICS-Park Smart Park Management System v2.0

Proof of Concept (PoC) for CVE: 2017-16744 and 2017-16748

ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE


Fuzzer for the Sparkplug B IIoT protocol

Modbus Packet Injection on Advantech WISE 4060LAN / IoT Gateway for door control

Schneider Electric Magelis HMI Resource Consumption Vulnerabilities [ICSA-16-308-02, CVE-2016-8367, CVE-2016-8374]

There is a path injection vulnerability in OpenPLC-v3, which arises from the program not performing any validity checks on the file path parameters…