
WhatCMS
Shell-based CMS detection and exploit kit identifying 330+ content management systems, then launching automated security audits and exploitation…

Shell-based CMS detection and exploit kit identifying 330+ content management systems, then launching automated security audits and exploitation…

An open-source, pentest and developer-oriented web browser, using the power of Lua

The collaborative web app pentest suite

Open-source AI-powered 5-phase VAPT pentest agent — recon/scan/vuln/exploit/report with PoC

pentest on MagnoHost hosting provider & MeteorCloud infrastructure with 15+ servers mapped. Findings: MariaDB exposed on 6 servers, OmniDialer…

A collection of hacking tools, resources and references to practice ethical hacking.

network visualization & pentest reporting

Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements,…

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Arsenal is just a quick inventory and launcher for hacking programs

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

A Burp Suite Extension for pentester and bug bounty hunters an to maintain checklist, map flows, write test cases and track vulnerabilities

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

Exploit For: CVE-2024-39123: Stored XSS in Calibre-web 0.6.21

Collection of pentesting scripts

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

All about bug bounty (bypasses, payloads, and etc)