
theo
Ethereum recon and exploitation tool.

Ethereum recon and exploitation tool.

Modular VoIP penetration testing toolkit with tools for SIP/RTP fuzzing, man-in-the-middle attacks, SRTP decryption, VLAN enumeration, and…

Search and download public exploits from the Vulners database — online, or fully offline from a local SQLite FTS5 index.

Find exploits in local and online databases instantly

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Penetration tests guide based on OWASP including test cases, resources and examples.

A Ruby framework designed to aid in the penetration testing of WordPress systems.

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

A list of resources for those interested in getting started in bug bounties

Program for determining types of files for Windows, Linux and MacOS.

Curated collection of Windows kernel privilege escalation exploits, organized by CVE/MS bulletin, with source code and references for penetration…

All about bug bounty (bypasses, payloads, and etc)

One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

Curated collection of Linux kernel privilege escalation exploits indexed by CVE, with proof-of-concept code for penetration testing and vulnerability…

Autonomous AI-driven red team agent that executes realistic attack chains—reconnaissance, exploitation, privilege escalation, lateral movement, and…

📡 Comprehensive collection of OSINT tools for cybersecurity professionals, researchers, and bug bounty hunters. Topics: information gathering,…

Curated collection of web attack payloads for XSS, SQLi, command injection, and more. Includes fuzzing lists, password wordlists, and CTF-sourced…