#1デフォルトの認証情報をすべて一箇所にまとめ、Blue/Redチームがデフォルトパスワードのデバイスを特定するのを支援します 🛡️

Netwave IPカメラからメモリダンプの脆弱性(CVE-2018-17240)を利用してログイン認証情報を取得するツール

組み込みデバイスセキュリティ評価フレームワーク — 700モジュール、350 CVE、55ベンダー、APTグループエンジン。ルーター、IPカメラ、GPON ONT、ISP CPE、IoT/組み込みエッジをカバー。

CVE-2026-61500 の Python PoC と Docker ラボ: Rejetto HFS V8 の PRNG 状態を復元して管理者セッション Cookie を偽造し、server_code を介して RCE を達成します。

Remote operations commands implemented using Beacon Object Files

A curated list of penetration testing and ethical hacking tools, organized by category. This compilation includes tools from Kali Linux and other…

依存関係不要のPython PoCジェネレーターで、CVE-2025-24071向けにZIP内に悪意のある.library-msファイルを作成し、Windows ExplorerのNTLMハッシュ漏洩を引き起こします。

Python3で書かれたWeb脆弱性スキャナー

WordPress Coreの認証前RCEチェーンCVE-2026-63030およびCVE-2026-60137(SQLインジェクションからリモートコード実行への連鎖)に対応するPython製のマスエクスプロイトおよび検出ツール。

これは、Linuxシステム上でワイヤレスネットワークを監査するための多用途bashスクリプトです。

OSCP notes vault + exam cockpit dashboard: merged technique notes, variable-filled command decks, machines, creds, and runbook for exam day. MIT.

EthPress <= 2.3.5 の未認証認証バイパスを悪用し、ウォレットアドレス経由で WordPress 管理者セッションを取得する検証済みの概念実証(PoC)。

Local-network security auditing with EOL, CVE, device identity, and HTML reports

自動化されたペネトレーションテストフレームワーク - オープンソースの脆弱性スキャナー - 脆弱性管理

TrustedSec チームによる、Hashcat を通じてクラッキング手法を自動化するツール。

Curated collection of Hashcat password-cracking rules with benchmark data, designed to help red teams and penetration testers crack complex passwords…
