

PhantomRecon is a CLI-based, modular, agent-driven red team automation tool designed to demonstrate autonomous offensive security workflows powered…

Automating the MITM attack on WSUS

WordPress Core Pre-Auth RCE — バッチルート混乱 + SQLインジェクション

読み取り専用のEntra IDアプリ資格情報評価:Graphの権限、Azure RBAC、到達可能なクラウドデータを列挙し、調査結果を権限昇格と横移動の経路にマッピングします。

バグバウンティ作業中に使用するスクリプトとツールのコレクション。ここは、個人利用のために作成し、時折公開リリースする自動化スクリプトの置き場所になります。

CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft →…

Rail-OT-Protector (ROP) — free, open-source cybersecurity scanning tool for rail and transit OT/SCADA networks. PowerShell + Bash scanners for…

Qtベースのデジタル信号アナライザー。SuscanコアとSigutils DSPライブラリを使用。

python code use to check for user in ssh

Microsoft Entra ID (Azure AD) 未認証列挙

RF CHAOS is an Android App That Is Designed To Cause Chaos via All RF Adapters Possible - Enjoy!

ウェブサイトとJSファイルをスキャンして露出したGemini APIキーを検出し、それらをライブで検証、アクセス可能なサービスを列挙し、APIを直接利用するためのブラウザクライアントを提供します。

Google Maps APIキーを21のエンドポイントに対して検証し、PoC URL付きで露出したサービスを明らかにします。プロキシサポートと集中監査のためのクワイエットモードを備えています。

WordPress 向け CVE-2026-63030 / CVE-2026-60137 セキュリティツールは、WP2Shell 事前認証 RCE チェーンへの曝露を検出します。

HTTPヘッダーと非破壊的なログインフォームプローブを介して、PHP CVE-2026-17543の曝露を検証する安全なPowerShellバリデータ。

WordPress All-in-One Exploit Framework — 検出、スキャナー、列挙、エクスプロイト、権限昇格。2026-08 の波から10件のCVE(CVE-2026-63030(wp2shell)を含む)。

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications