Stars
Agentic pentest tooling. Currently achieving 81% (KIMI K2.5) on XBOW's benchmark in full black-box. Completely Self-hosted. Every model available on LiteLLM (Ollama, anthropic, openai...)
Abuse trust-boundaries to bypass firewalls and network controls
Burp Plugin to Bypass WAFs through the insertion of Junk Data
CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting) vulnerabilities on sites where injections are blocke…
A small command-line utility to artificially limit the input rate to STDIN.
A fast, simple, recursive content discovery tool written in Rust.
The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
A cheatsheet for exploiting server-side SVG processors.
Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!
MassDNS wrapper written in go to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard filtering and easy input-output support.
Generates permutations, alterations and mutations of subdomains and then resolves them
PwnFox is a Firefox/Burp extension that provide usefull tools for your security audit.
RCE 0-day for GhostScript 9.50 - Payload generator
Self contained htaccess shells and attacks
A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.
This repository includes a set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard certificate. The objective is to simplify as much as possible t…
Base64-based encryption oracle exploit for CVE-2017-9248 (Telerik UI for ASP.NET AJAX dialog handler)
Enables full-text searching of CouchDB documents using Lucene
Easily turn single threaded command line applications into a fast, multi-threaded application with CIDR and glob support.