


High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

Hide your Powershell script in plain sight. Bypass all Powershell security features

🐱💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks

Xss Payload Generator ~ Xss Scanner ~ Xss Dork Finder


IP obfuscator made to make a malicious ip a bit cuter

Remote Code Injection In Log4j

This script automates SQL injection testing using SQLMap with AI-powered decision making.

A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It…

Stuff that doesn't deserves its own repository.

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.

Encoder to bypass WAF filters using XOR operations.

Automated Tool That Generates The Perfect Meterpreter Powershell Payload

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.