
Doozer
Password cracking utility

Password cracking utility

Some Pentest Tools. Install and keep up to date some pentesting tools. I used this to pass my OSCP exam.

A Magisk module that simplifies running the Frida server on Android, with easy management commands to download specific versions, enable or disable…

Extension adds a new tab in Burp Suite called Extractor

RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…

Agent-native CLI wrapping IDA Pro IDALib for stateless, JSON-output binary analysis: disassembly, Hex-Rays decompilation, CFG, xrefs, strings, and…

Human-friendly Thrift encoder/decoder

100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI

A Android malware analysis tool that creates comprehensive runtime profiles by hooking into application behavior across cryptography, file systems,…

SleuthQL是基于python3所开发的一款,用于批量爬行站点可能存在sql的地址。并且可以配合burp+sqlmap进行批量注入。 对比sqlmap手动单线程一个一个注入点的去识别,方便了很多。

Native HTTP/HTTPS interception proxy for penetration testers and bug bounty hunters with live request tampering, request replay, high-speed fuzzing,…

Terminal-based HTTP intercepting proxy with TUI for capturing, inspecting, and modifying requests in real time, plus a Repeater for resending and…

Self-hosted SSRF redirect, payload, callback, and DNS workbench

Content-blind reverse proxy for exposure-protected security scanning

Local-first macOS research browser built on a custom Brave build that captures network traffic, fingerprints, scripts, and runtime evidence for…

Extract the managed (.NET) assemblies out of a MAUI Android assembly store.

C++ reimplementation of Ghidra's analytical core without JVM dependencies, providing embeddable binary analysis, Pcode/Sleigh foundations, and…

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…