
wp2shell-vulnerability-scanner
Scan WordPress installations for wp2shell vulnerabilities (CVE-2026-63030 + CVE-2026-60137). Identifies full RCE and SQL injection risks across…

Scan WordPress installations for wp2shell vulnerabilities (CVE-2026-63030 + CVE-2026-60137). Identifies full RCE and SQL injection risks across…

Suite for reverse shell handling geared toward working within the native shell

Multi-language detection scripts for CVE-2025-55182 (React2Shell) that scan package.json files to identify vulnerable React dependency versions and…

Automatically run and save ffuf scans for multiple IPs

Find Electron Apps Vulnerable to CVE-2023-4863 / CVE-2023-5129

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

PowerShell-based scanner to detect Log4j CVE-2021-44228 vulnerability by searching directories and log files for exploitation indicators.

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

WebLogic WLS核心组件反序列化漏洞多线程批量检测脚本 CVE-2018-2628-MultiThreading

The Symfony PHP framework

Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.

Exploits Scripts and other tools that are useful during Penetration-Testing or Red Team engagement

AES-256 file and directory encryption tool with interactive CLI, progress bar, and optional secure deletion of originals. Supports large files and…

Just a repo of random Python scripts to get pentesters started with the Python language on engagements.

Feature toggle framework for Java enabling runtime feature activation, role-based access, AOP-driven toggling, monitoring, audit trails, and a web…

Static detection of vulnerable log4j librairies on Windows servers, members of an AD domain.

Aggressor scripts for phases of a pen test or red team assessment