
naabu
A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface…

A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface…

Adversary Emulation Framework

Python PoC scanner and exploit for CVE-2026-84434, an unauthenticated arbitrary file upload in Gravity Forms <=3.1.0.4 via hidden File Upload fields.…

Vendor-neutral NDJSON attack-graph format with node/edge taxonomy, AWS/GCP/Azure mappings, derivation rules, and an exposure DB for offensive…

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

The TTPForge is a Cybersecurity Framework for developing, automating, and executing attacker Tactics, Techniques, and Procedures (TTPs).

A network stress testing tool for simulating high traffic loads.

Generate wordlists using pattern logic and expressions.

Configure your Pi Zero 2W to be a BadUSB

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

This script will attempt to mitigate the copy_fail attack. CVE-2026-31431

Performed a live cybersecurity assessment on a university Linux server. During analysis, active attack activity was identified, including brute-force…

Wireless penetration testing framework. Automates WPA/WPA2/WEP/WPS attacks - recon to exploitation in one command. aircrack-ng + hashcat + PMKID.

In-depth attack surface mapping and asset discovery

BurpFlow is one of the best Burp Suite automation tools for bug bounty hunters and penetration testers, widely used to load recon data via proxy and…

**HashEye** is a powerful Python CLI tool for instantly detecting and analyzing hash types. It provides detailed information about hash formats,…

Attack surface discovery and AI-assisted triage for security researchers. Endpoint & parameter mapping with actionable testing hints.

Modular toolkit for pentesters that converts Burp Suite captured HTTP requests into browsable URLs and automates workflow actions with auditable…