
laf
This project intends to provide a series of tools to craft, parse, send, analyze and crack a set of LoRaWAN packets in order to audit or pentest the…

This project intends to provide a series of tools to craft, parse, send, analyze and crack a set of LoRaWAN packets in order to audit or pentest the…

Set of tools to assess and improve LLM security.

Search Google/Bing/Ecosia/DuckDuckGo/Yandex/Yahoo for a search term (dork) with a default set of websites, bug bounty programs or custom collection.

Set of tools to analyze Windows sandboxes for exposed attack surface.

WVCTF or WebVulnCTF is a gamified web platform which promotes training in pentesting and web application development security in an entertaining way.…

A Zeek package for the passive detection of "Ripple20" vulnerabilities in the Treck TCP/IP stack.

Determine privileges from cloud credentials via brute-force testing.

Finding Ethereum nodes which are vulnerable to RPC-attacks

Proof-of-concept exploit for OS command injection (CVE-2023-33381) in MitraStar GPT-2741GNAC routers. Demonstrates bypass of restricted shell via…

sample exploit of buffer overflow in libpng

Lightweight Python checker that tests Active Directory credentials for exposure to CVE-2022-33679 (Kerberos AS-REP roast without pre-authentication).…

Proof-of-concept exploit for CVE-2025-53367, a vulnerability in the DjVuLibre library. Demonstrates exploitation of a memory corruption bug in DjVu…

Tools collection to explore CVE and theirs associated data.

A tool for checking if MFA is enabled on multiple Microsoft Services

A cheatsheet for exploiting server-side SVG processors.

Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier

Proof-of-concept for CVE-2023-4863, a heap buffer overflow in WebP image decoding. Demonstrates the code_lengths trigger mechanism discovered by…

Toolkit to weaponize Chromium vulnerabilities into reliable, cross-platform, full-chain exploits