
HackTools
The all-in-one browser extension for offensive security professionals 🛠

The all-in-one browser extension for offensive security professionals 🛠


Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

Create tar/zip archives that can exploit directory traversal vulnerabilities

A simple tool for bypassing file upload restrictions.

This script automates SQL injection testing using SQLMap with AI-powered decision making.

Never forget where you inject.


Swiss army knife Webserver in Golang. Keep simple like the python SimpleHTTPServer but with many features

Web Backdoor Cookie Script-Kit

For pentesters who don't wanna leave their terminals.

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.

MalQR is a collection of malicious QR Codes and Barcodes you can use to test the security of your scanners.


php-fpm+Nginx RCE

XSSYA (Cross Site Scripting Scanner & Vulnerability Confirmation)

Python library for Turbo Intruder that adds payload position support and Sniper/Clusterbomb/Pitchfork attack types with tag-based test generation for…

Stealthy PHP webshell disguised as a 404 error page with AJAX console, hidden command execution via Referrer header, and preconfigured actions for…