
shennina
Automating Host Exploitation with AI

Automating Host Exploitation with AI

The most powerful CRLF injection (HTTP Response Splitting) scanner.

Smart ssrf scanner using different methods like parameter brute forcing in post and get...

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

This script communicates with the Nessus API in an attempt to help with automating scans. Depending on the flag issued with the script, you can list…

Now, the Host is Mine! - Super Fast Sub-domain Takeover Detection!

Multi-threaded web fuzzer for URL path, HTTP header, and POST data brute-forcing with proxy support, status code filtering, and reflexive content…

dSploit - The most complete and advanced IT security professional toolkit on Android.

Linux post exploitation privilege escalation enumeration

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading

Nuclear Pond is a utility leveraging Nuclei to perform internet wide scans for the cost of a cup of coffee.

Time-based blind SQL injection detection tool for recon and bug bounty. Accepts single URLs or lists, supports custom headers, proxy, and POST data…

A better version of my xssfinder tool - scans for different types of xss on a list of urls.

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

Ghazi is a BurpSuite Plugins For Testing various PayLoads Like "XSS,SQLi,SSTI,SSRF,RCE and LFI" through Different tabs , Where Each Tab Will Replace…

Runtime vulnerability scanner: finds CVEs in the services actually running on a host and ranks them by network exposure.

Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.

Log4j 漏洞本地检测脚本。 Scan all java processes on your host to check whether it's affected by log4j2 remote code execution vulnerability (CVE-2021-45046)