
violin
Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Modular memory webshell generator supporting Java containers (Tomcat, Spring, WebLogic) with multiple shell types, encoders, and automatic…

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

FreePBX CVE-2025-57819 lab (Docker) + Nuclei POC for unauth SQLi (time-based).

this is a metasploit exploit module for CVE-2024-25096 and CVE-2023-3452

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft →…