


Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

Fast and easy-to-use directory brute-forcer written in Go.

Python PoC for CVE-2023-6063, an unauthenticated time-based blind SQL injection in WP Fastest Cache <=1.2.2, extracting WordPress password hashes and…

Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF…

Advanced network penetration testing toolkit with SSH vulnerability assessment, CVE-2018-15473 exploitation, stealth brute force capabilities, and…

Hash-based malware scanner for incident response. Scans files recursively using known malware hashes, supports multithreading, extension filtering,…

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

An easy to use, light-weight, on-demand virus scanner for Linux systems. For additional help, see the <a…

DirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it

A comprehensive Python-based security tool for file scanning, malware detection, and analysis in an ever-evolving cyber landscape.

Brute Hikvision CAMS with CVE-2021-36260 Exploit

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…

Automatically brute force all services running on a target.

Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

Bash and PowerShell scripts to scan a local filesystem for Log4j .jar files which could be vulnerable to CVE-2021-44228 aka Log4Shell.

Probe and discover HTTP pathname using brute-force methodology and filtered by specific word or 2 words at once

Smart ssrf scanner using different methods like parameter brute forcing in post and get...