
WordList
Curated collection of custom wordlists for fuzzing, DNS enumeration, parameter discovery, and default credentials, plus a Go generator for nuclei…

Curated collection of custom wordlists for fuzzing, DNS enumeration, parameter discovery, and default credentials, plus a Go generator for nuclei…

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…

Production-grade Security Baseline & Hardening Guide for Ubuntu 24.04/26.04 LTS. Kernel isolation, Emergency Panic Button, custom AppArmor/Firejail…


Aggregate, filter, and track CVEs from multiple sources with team collaboration, custom dashboards, alerts, and AI-powered analysis for vulnerability…

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含

Time-based blind SQL injection detection tool for recon and bug bounty. Accepts single URLs or lists, supports custom headers, proxy, and POST data…

a CLI for ephemeral penetration testing

a security scanner for custom LLM applications

Next.js-Exploit-Tool 图形化综合利用工具,基于 Go 开发,一款针对 CVE-2025-55182 的独立安全评估工具。

Python-based GUI wrapper for Nmap providing speed scanning, custom service detection, and user-controlled parameters for network reconnaissance and…

Nuclei template providing a proof-of-concept for CVE-2024-4577, a PHP CGI argument injection vulnerability, enabling automated detection and testing.

BurpSuite插件,用于自动化执行blind-xss盲搜索。它能够执行主动和被动检查。