
WhatWeb
Next generation web scanner

Next generation web scanner

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.

Xss Payload Generator ~ Xss Scanner ~ Xss Dork Finder


Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

nginx CVE scanner + RCE exploit framework (CVE-2026-42945 + 16 others)

Freeze is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls, and alternative execution methods

Automated Tool That Generates The Perfect Meterpreter Powershell Payload


A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It…

Modular password sprayer with SSH proxy rotation, MFA bypass, and domain recon. Supports O365, ADFS, OWA, Okta, Cisco VPN. Automates credential…

This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

🐱💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks

Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to…

Tests hundreds of URL bypass techniques against 40X protected pages using raw curl requests, with multi-mode scanning, header spoofing, and JSON/HTML…
