
ADRecon
PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

Newfold plugins (wp-module-data <= 2.9.7) Unauthenticated

Single-file Python scanner and exploit for CVE-2026-85706, an unauthenticated arbitrary file read in self-managed GitLab CE/EE, with project…

Modular post-exploitation framework managing reverse-shell sessions over TCP/TLS/mTLS with plugins for enumeration, in-memory execution, SOCKS5…

Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs) using 6 free Threat Intel APIs. Outputs: Color-coded Excel, JSON, CSV. Uses: VT, Shodan,…

The official Python 3 client library for VirusTotal

Asynchronous RDP client for Python (headless)

Perl script to test the reliability of a list of open web proxies.

SleuthQL是基于python3所开发的一款,用于批量爬行站点可能存在sql的地址。并且可以配合burp+sqlmap进行批量注入。 对比sqlmap手动单线程一个一个注入点的去识别,方便了很多。

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

Cortex: a Powerful Observable Analysis and Active Response Engine

Web-based red team activity logging, reporting, and situational awareness tool with Cobalt Strike and BloodHound integration.

Extract parameters/paths from urls

Modular toolkit for pentesters that converts Burp Suite captured HTTP requests into browsable URLs and automates workflow actions with auditable…

Bash script for DNS resolution checking, enabling quick domain-to-IP lookups and basic network reconnaissance from the command line.

HTTP Web Server probing

A fast port scanner written in go with a focus on reliability and simplicity.

Finds public elite anonymity proxies and concurrently tests them