
CapTipper
Malicious HTTP traffic explorer

Malicious HTTP traffic explorer

Async-based exploit tool for CVE-2025-5777 that detects and extracts leaked authentication tokens, internal IPs, and hidden endpoint paths from…

This Python application scans for the CVE-2023-38831 vulnerability in WinRAR.

White-box CMS security scanner that audits core, plugin, and theme versions, detects unauthorized modifications, and cross-references known…

Analyzes Nginx access logs to detect SQL injection, scanner tools, webshells, and exploitation attempts, aiding system administrators in server…

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Security testing tool for analyzing HTTP 403 responses and identifying access control misconfigurations in web applications.


Disrupt WAF by abusing SSL/TLS Ciphers

Cyber threat intelligence platform for SSL certificate discovery, domain/URL scanning, data leak monitoring, tracking link generation, and threat…

Systematic reverse engineering of Cisco ASA's lina binary to discover and analyze memory corruption vulnerabilities, including CVE-2025-20333 and…

Automated Web Vulnerability Assessment of DVWA using OWASP ZAP to identify and analyze critical security flaws like Remote Code Execution…

Reproduction environment for CVE-2025-13465, demonstrating a vulnerability in Next.js applications using Lodash. Provides a minimal setup to test and…

Vimana is a modular security framework for auditing Python APIs and Web applications. The plugin-based architecture enables security professionals to…

A source code static analysis platform for AppSec enthusiasts.

Documents and identifies 2,953 Chrome extensions silently probed by LinkedIn, providing tools to fetch extension names and analyze browser…

Your Swiss Army knife to analyze malicious web traffic based on the popular Fiddler web debugger.

Burp Suite extension for decoding Web3 JSON-RPC traffic, including smart contract function calls, responses, and ABI resolution with proxy-aware and…