
cookiemonster
Decodes and unsigns vulnerable session cookies from Django, Flask, Laravel, Express, and JWT frameworks. Supports HMAC-based decoders, base64…

Decodes and unsigns vulnerable session cookies from Django, Flask, Laravel, Express, and JWT frameworks. Supports HMAC-based decoders, base64…

Exploit Microsoft Zero-Day Vulnerability Follina (CVE-2022-30190)

A command line Windows API tracing tool for Golang binaries.

Interactive cli tool for HTTP inspection

A command-line utility for Windows written in C that creates and configures persistent Event Tracing for Windows (ETW) AutoLogger sessions.

CLI and interactive console for listing, browsing, and extracting files from VM disk images (VHDX, VMDK, EBS snapshots, raw disks) for red-team…

A lightweight tool for orchestrating and organizing your bug hunting recon / pentesting command-line workflows

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

Command-line and Python debugger for instrumenting and modifying native software behavior on Windows and Linux.

GodOfWar - Malicious Java WAR builder with built-in payloads

SSHBuster is a powerful command-line SSH brute-forcing tool designed for ethical hacking and penetration testing. It performs dictionary-based…

Command-line tool that allows searching and downloading app packages (known as ipa files) for iOS, iPadOS, tvOS, and visionOS from the App Store.

A tool to quickly do keyword searches over Gitlab and Github for OSINT & bug bounty recon

A tool to monitor local network traffic for possible security vulnerabilities. Warns user against possible nmap scans, Nikto scans, credentials sent…

Download the entire Wayback Machine archive for a given URL.


CVE-2025-55182 & CVE-2025-66478 Detection Tool for Next.js RSC RCE

Concurrent CLI tool for discovering secrets, API keys, and links in JavaScript files during web reconnaissance, with custom regex pattern support and…