
droidlysis
Automated pre-analysis tool for Android apps that disassembles samples, extracts properties via configurable pattern matching, and organizes output…

Automated pre-analysis tool for Android apps that disassembles samples, extracts properties via configurable pattern matching, and organizes output…

test struts2 vulnerability CVE-2017-5638 in Mac OS X

Find exposed API keys based on RegEx and get exploitation methods for some of keys that are found

Brute-force tool for discovering hidden GET and POST parameters in web applications, supporting custom wordlists and concurrent requests.

test for CVE-2018-6574: go get RCE pentesterlab

Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting

Exploit for CVE-2025-64512 to get a reverse shell.

CVE-2018-6574: go get RCE solution for pentesterlab challenge

Dynamically extracts fresh syscall stubs from ntdll.dll to evade signature-based detection, with a shellcode execution template for Nim-based…

Binary code coverage visualizer plugin for Ghidra

Azure mindmap for penetration tests

PowerShell module for automatic detection of P/Invoke, Dynamic P/Invoke, and D/Invoke in .NET assemblies. Reveals unmanaged API calls, MDTokens, and…

Scans exported Azure domain dumps for plaintext passwords, connection strings, storage keys, and other secrets; generates redacted CSV/HTML reports…

Proof-of-concept exploit for CVE-2017-1000367, a local privilege escalation vulnerability in Sudo's get_process_ttyname() on Linux, allowing…

Go-based WinRM client for remote command execution and lateral movement on Windows systems during penetration tests.

Exploit for remote command execution in Golang go get command.

Automated deployment of OWASP Juice Shop on Kubernetes using kubeadm and Terraform, with integrated Trivy vulnerability scanning for DevSecOps…