
Kubestroyer
Go-based Kubernetes exploitation tool that scans for exposed ports and exploits cluster misconfigurations, including anonymous Kubelet RCE and etcd…

Go-based Kubernetes exploitation tool that scans for exposed ports and exploits cluster misconfigurations, including anonymous Kubelet RCE and etcd…

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab:

Python-based web security scanner that analyzes HTTP headers, SSL/TLS, DNS records, and common misconfigurations to generate a scored security report…

Black-box Kubernetes attack surface discovery tool that probes for unsecured clusters, exposed dashboards, and misconfigurations using…

XSS scanner that detects Cross-Site Scripting vulnerabilities in website by injecting malicious scripts

A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.

FireShodanMap is a Realtime map that integrates Firebase, Google Maps and Shodan. A search is carried out using Shodan searching vulnerable devices…

openrisk is a tool that generates a risk score based on the results of a Nuclei scan.

A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as…

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…

HTTP stress testing tool that can overload web servers.

Shodan-powered vulnerability scanner that discovers exposed devices and scans targets for known CVEs and vulnerabilities using dork queries and IP…

Scans AWS IAM configurations for shadow admins by detecting misconfigured deny policies that fail to restrict user actions on groups, enabling…

Fast subdomain takeover scanner that checks DNS CNAME records against known fingerprints to detect vulnerable subdomains. Built in Go with…

Automated reconnaissance and vulnerability detection tool that enumerates subdomains, collects URLs, and runs Nuclei scans to identify…

This tool allows to check speculative execution side-channel attacks that affect many modern processors and operating systems designs. CVE-2017-5754…

Cake Fuzzer is a project that is meant to help automatically and continuously discover vulnerabilities in web applications created based on specific…