
pentest-pivoting
A compact guide to network pivoting for penetration testings / CTF challenges.

A compact guide to network pivoting for penetration testings / CTF challenges.

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

Burp Suite extension to perform Kerberos authentication

Caches JWT authentication tokens from an auth URL and attaches them as headers to in-scope requests in Burp Suite for automated session handling.

HTTP/HTTPS interception proxy for testing Windows authentication mechanisms, supporting NTLM, Kerberos, pass-the-hash, pass-the-ticket and relay…

AIO Cloud Managment Server

Just-in-time API keys for AI agents - and any other process you route through it: the caller only ever sees a placeholder.

Mirror moved — see GitHub and Codeberg

Proof of concept for CVE-2017-6640 as burp extension

Exploit for Dahua camera authentication bypass (CVE-2021-33045) using mitmproxy to intercept and modify login requests to /RPC2_Login.

Squid Web Proxy Cache - Source Code

A HTTP credential proxy and vault for AI agents like Claude Code, OpenClaw, Hermes, custom agents + harnesses, and more.

Fast TCP/UDP tunnel over HTTP with SSH encryption, supporting reverse port forwarding, SOCKS5 proxy, and client authentication for secure network…

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

HTTP/HTTPS proxy over SSH

Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS…

SOCKS5-to-HTTP proxy bridge that tunnels arbitrary TCP streams (SSH, SMTP, TLS) through standard HTTP requests, enabling network traffic obfuscation…