Threat framework to research security gaps in GraphQL implementations.
Abusing Certificate Transparency logs for getting HTTPS websites subdomains.
Fileshare auditing tool.
Gather and update all available and newest CVEs with their PoC.
Some setup scripts for security research tools.
Divide full port scan results and use it for targeted Nmap runs.
Yet another subdomain finder.
A list of disposable and temporary email address domains.
HTA encryption tool for Red Teams.
Finds Directory Listings or open S3 buckets from a list of URLs.
Automatically brute force all services running on a target.
Create a copy of a targeted website with CDN and WAF restrictions disabled.
Crawl a site and extract useful informations for recon.
Obfuscation script designed to bypass AMSI and commercial antivirus solution.
Smart context-based SSRF vulnerability scanner.