
akto
Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

A secure low code deception runtime framework, leveraging AI for System Virtualization.

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

Perl-based web server scanner that performs comprehensive vulnerability checks, CGI scanning, and server fingerprinting with customizable plugins and…

Operational security controls with forensic guarantees

Reproducer for CVE-2026-46592 demonstrating SOAP operation redirection via operationName header injection in Apache Camel camel-cxf, enabling…

Reproducer for CVE-2026-46726 demonstrating WebSocket header injection in Apache Camel camel-vertx-websocket enabling SSRF and property-placeholder…

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Technical documentation and reverse engineering analysis of Google's reCAPTCHA anti-bot system, covering payload structure, obfuscation techniques,…

Multi-architecture Docker toolkit for penetration testing with preconfigured tools for web, network, mobile, API, OSINT, and forensics. Features…

The Swiss Army knife for automated Web Application Testing

Fuzzing Framework for Modules in Apache HTTPD Server

Free DPI bypass tool using a Google Apps Script relay with TLS SNI concealment. Provides HTTP and SOCKS5 proxy, cross-platform desktop UI, and no…

Differential testing framework for HTTP implementations

CLI tool for automated detection of server-side and client-side template injection vulnerabilities across 44 template engines in 8 programming…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…