
TIWAP
Deliberately vulnerable Flask web application with 22 security flaws across 3 difficulty levels for hands-on penetration testing and web security…

Deliberately vulnerable Flask web application with 22 security flaws across 3 difficulty levels for hands-on penetration testing and web security…

Offensive Docker is an image with the more used offensive tools to create an environment easily and quickly to launch assessment to the targets.

CVE-2019-0708-Msf-验证

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

Vagrant VirtualBox environment for conducting an internal network penetration test

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more

Modular penetration testing framework integrating multiple tools for automated web application security assessment, aligned with OWASP Testing Guide,…

Bash script wrapping Active Directory tools for automated enumeration, vulnerability checks, exploitation, and password dumping via LDAP, RPC,…

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.

Metasploit-Framework modules (scanner and exploit) for the CVE-2021-41773 and CVE-2021-42013 (Path Traversal in Apache 2.4.49/2.4.50)

No-dongle, no-root Bluetooth security assessment tool for wireless earbuds affected by the Airoha SDK vulnerability chain (CVE-2025-20700/20701/20702)

An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents

Hakku Framework penetration testing

FAST WEB APPLICATION VULNERABILITY SCANNER written in python3

A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It…