
Oihk-pentesting
Autonomous multi-agent AI penetration-testing engine: a governed tool sandbox, an immutable evidence-and-validation gate, and a reproducible…

Autonomous multi-agent AI penetration-testing engine: a governed tool sandbox, an immutable evidence-and-validation gate, and a reproducible…

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

Another tool for subdomain enumeration with some magics 🧙🏻♂️

Static detection of vulnerable log4j librairies on Windows servers, members of an AD domain.

Web vulnerability scanner focused on automated XSS/CSP bypass payload testing and batch SQL injection detection, using SQLMap and reporting only…

Serverless AWS solution for distributing recon and vulnerability scanning workloads. Submit tasks via web UI; EC2 workers execute custom Python…

SleuthQL是基于python3所开发的一款,用于批量爬行站点可能存在sql的地址。并且可以配合burp+sqlmap进行批量注入。 对比sqlmap手动单线程一个一个注入点的去识别,方便了很多。

Cortex: a Powerful Observable Analysis and Active Response Engine

Bash script for DNS resolution checking, enabling quick domain-to-IP lookups and basic network reconnaissance from the command line.

A collection of awesome one-liner scripts especially for bug bounty tips.

Detect & clean up wp2shell (CVE-2026-63030) WordPress compromise — bulk-runnable, read-only by default

Identifying all log4j components across all windows servers, entire domain, can be multi domain. CVE-2021-44228

A powershell script to deploy the registry mitigation key for CVE-2020-1350

Dynamically generated Suricata rules from real-time threat feeds

Mitigation scripts for CVE-2026-50751