

PhantomRecon is a CLI-based, modular, agent-driven red team automation tool designed to demonstrate autonomous offensive security workflows powered…

🎯 CVE-2025-53770의 영향을 받는 SharePoint 서버용 취약점 스캐너입니다. ToolPane.aspx와 조작된 base64+gzip 페이로드를 사용하여 안전하지 않은 역직렬화를 감지합니다. 🛡️ Ahmed Tamer가 개발했습니다.

CRLF 기반 desync 공격을 위한 Nuclei 템플릿 및 익스플로잇 리소스

WordPress 코어 사전 인증 RCE — 배치 라우트 혼동 + SQL 인젝션

CVE-2026-56164는 온프레미스 Microsoft SharePoint Server에 영향을 미치는 치명적인 인증 누락 취약점입니다. 인증되지 않은 원격 공격자가 네트워크를 통해 권한을 상승시킬 수 있습니다.

Palo Alto - CVE-2026-0300 exploit

Rail-OT-Protector (ROP) — free, open-source cybersecurity scanning tool for rail and transit OT/SCADA networks. PowerShell + Bash scanners for…

Rust 기반 HTTP 요청 스머글링 스캐너.

CVE-2026-31431("Copy Fail") — Linux 커널 algif_aead LPE를 위한 방어적 탐지 및 완화 도구입니다. 익스플로잇 코드는 포함되어 있지 않습니다.

Milvus 인증 보안 탐지 스크립트: CVE-2025-64513 (sourceid 백도어) / CVE-2026-26190 (/expr 약한 토큰) / 내부 포트 53100

Code and data for our paper "Onelogon: Taking over Active Directory Accounts via Netlogon" (WOOT’26).

Google Maps API 키를 21개 엔드포인트에 대해 검증하여 PoC URL과 함께 노출된 서비스를 식별하며, 프록시 지원 및 집중 감사를 위한 quiet 모드를 제공합니다.

CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing

WP2Shell 사전 인증 RCE 체인에 대한 노출을 탐지하는 WordPress CVE-2026-63030 및 CVE-2026-60137 보안 도구

HTTP 헤더 및 비파괴적 로그인 폼 프로브를 통해 PHP CVE-2026-17543 노출을 검증하는 안전한 PowerShell 검증기

WordPress All-in-One Exploit Framework — 탐지기, 스캐너, 열거자, 익스플로잇, 권한 상승. 2026-08 웨이브의 CVE 10개, CVE-2026-63030(wp2shell) 포함.

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).