
tmux
Terminal multiplexer for managing multiple shell sessions from a single screen, with session persistence, window splitting, and scriptable…

Terminal multiplexer for managing multiple shell sessions from a single screen, with session persistence, window splitting, and scriptable…

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Chaos Engineering Toolkit & Orchestration for Developers

✨ A high-performance plugin manager and toolkit for Zsh.

Module-based web vulnerability scanner and bug bounty automation framework with built-in XSS, SSTI, SSRF, and Firebase detection engines. Designed to…


Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

Multi-threaded mass exploiter chaining unauthenticated WordPress file-upload flaws in Super Forms and Elementor Pro to deploy and verify a PHP web…

Kali Linux VM images build script

Linux operating system for embedded devices with writable filesystem, package management, and build framework. Enables custom firmware creation for…

Python 3 PoC scanner and exploit for CVE-2026-92229, an unauthenticated arbitrary shortcode execution flaw in Forminator WordPress plugin versions…

Python PoC scanner and exploit for CVE-2026-89274, an unauthenticated arbitrary shortcode execution flaw in WP Recipe Maker <=10.8.1 via recipe…

PowerShell Module for automating tasks on remote systems using SSH

:triangular_flag_on_post: A CLI tool & library to enhance and speed up script/exploit writing with string conversion/manipulation.

Generates HTML smuggling pages that embed and reconstruct files client-side via JavaScript, with payload encoding, chunking, obfuscation, and…

Python CLI that exploits CVE-2026-48907 in Joomla JCE via profile-import upload, verifies shell paths, and opens an interactive command channel on…