Blog

Analysis, explainers and methodology notes. Articles are published in WordPress and rendered here at build time — their URLs are unchanged.

All posts

Tools

WP2Shell Vulnerability Checker – Test Your WordPress in Seconds

Check your WordPress site vulnerable to WP2Shell. Instant version checker, patch steps, WAF rules, detection scripts and IOCs for CVE-2026-63030 / CVE-2026-60137.

Published July 19, 2026
Uncategorized

T3MP3ST — Autonomous Red Teaming Platform

A multi-agent offensive-security framework, built to turn the AI coding agent you already run into a zero-day hunter.

Published July 6, 2026
Revers Engineering

SightHouse: Automated Function Identification for Reverse Engineering

SightHouse is an open-source tool developed by Quarkslab that helps reverse engineers automatically identify known functions inside binaries by matching them with previously analyzed code. SightHouse is a tool designed to assist reverse engineers by retrieving information and metadata from programs

Published April 3, 2026
AI

CISO Assistant — One-stop GRC Platform for Risk Management, AppSec

CISO Assistant offers a fresh perspective on Cybersecurity Management and GRC (Governance, Risk, and Compliance) practices: Features Upcoming features are listed on the roadmap. CISO Assistant is developed and maintained by Intuitem, a company specializing in Cybersecurity, Cloud, and Data/AI. Core

Published March 29, 2026
Android

AndroHunter – Android Security Research Toolkit

AndroHunter is a native Android application that provides a full suite of mobile security testing tools — all running directly on the device without requiring a rooted phone for most features. It is designed for security researchers participating in bug bounty programs (HackerOne, Yes We Hack, Intig

Published March 20, 2026
OSINT

WhatsApp Activity Tracker – Track WhatsApp by Phone Number

This project implements the research from the paper “Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant Messengers” by Gabriel K. Gegenhuber, Maximilian Günther, Markus Maier, Aljosha Judmayer, Florian Holzbauer, Philipp É. Frenzel, and Johanna Ullrich (Universi

Published December 12, 2025
Uncategorized

Username Finder

Published July 6, 2025
Python

PyXL – Python Directly in Hardware

What is PyXL? PyXL is a custom hardware processor that executes Python directly — no interpreter, no JIT, and no tricks. It takes regular Python code and runs it in silicon. A custom toolchain compiles a .py file into CPython ByteCode, translates it to a custom assembly, and produces a binary that r

Published April 28, 2025
OSINT

CF-Hero : Find Real IP Behind Cloudflare

CF-Hero is a comprehensive reconnaissance tool developed to discover the real IP addresses of web applications protected by Cloudflare. It gathers multi-source intelligence through various methods. DNS Reconnaissance Current DNS records (A, TXT) Historical DNS data analysis Associated domain discove

Published March 31, 2025
BugBounty

HExHTTP – HTTP Header Exploitation Tool

HExHTTP is a tool designed to perform tests on HTTP headers and analyze the results to identify vulnerabilities and interesting behaviors. Features Server Error response checking Localhost header response analysis Vhosts checking Methods response analysis HTTP Version analysis [Experimental] Cache P

Published January 28, 2025
Auth

Hanko – An Authentication and User Management Solution for the Passkey

Hanko is an open-source authentication and user management solution with a focus on moving the login beyond passwords while being 100% deployable today. Supports all modern authentication methods, incl. passkeys, social logins, and SAML SSO Highly flexible configuration options (e.g. optional/user-d

Published January 20, 2025
Social Media

Postiz – Free AI Social Media Scheduling Tool

Postiz: An alternative to: Buffer.com, Hypefury, Twitter Hunter, Etc… Postiz offers everything you need to manage your social media posts, build an audience, capture leads, and grow your business. Intro Schedule all your social media posts (many AI features) Measure your work with analytics. Collabo

Published January 20, 2025
OSINT

Maigret – Search Person by Username from Thousands of Sites

Maigret collects a dossier on a person by username only, checks for accounts on many sites, and gathers all the available information from web pages. No API keys are required. Maigret is an easy-to-use and powerful fork of Sherlock. Currently supports more than 3000 sites (full list), search is laun

Published January 20, 2025
Forensic Tool

Logicytics: System Data Harvester

Logicytics is a cutting-edge tool designed to meticulously harvest and collect a vast array of Windows system data for forensic analysis. Crafted with Python 🐍, it’s an actively developed project that is dedicated to gathering as much sensitive data as possible and packaging it neatly into a ZIP fi

Published September 23, 2024
AI

Dubbie – Open-source AI video dubbing studio

Dubbie is an open-source AI dubbing studio that costs $0.1/min, which is about ~20x less than alternatives like ElevenLabs, RaskAI, or Speechify. While still in early development and not at feature parity with these alternatives, Dubbie offers enough features to create dubs for basic videos. What is

Published August 21, 2024
Script

Hamster Kombat: Auto Clicker and Desktop Version

Everyone is now familiar with the trending telegram-based crypto game name Hamster Kombat, a game that blends adorable critters with the world of cryptocurrency, which is taking the internet by storm. This Telegram-based game has rocketed to popularity, boasting over 200 million users in a shockingl

Published July 1, 2024
Tools

GWPSan: Sampling-Based Sanitizer Framework

GWPSan is a framework for low-overhead sampling-based dynamic binary instrumentation, designed for implementing various bug detectors (also called “sanitizers”) suitable for production uses. GWPSan does not modify the executed code, but instead performs dynamic analysis from signal handlers. Usage T

Published June 10, 2024
AI

Agentic Security – LLM Security Scanner

Features Customizable Rule Sets or Agent based attacks🛠️ Comprehensive fuzzing for any LLMs 🧪 LLM API integration and stress testing 🛠️ Wide range of fuzzing and attack techniques 🌀 Note: Please be aware that Agentic Security is designed as a safety scanner tool and not a foolproof solution. It

Published May 7, 2024
Uncategorized

How to Make an Ultraviolet Proxy

Ultraviolet is a highly advanced web proxy used for evading internet censorship or accessing websites in a controlled sandbox. It is designed with security and performance in mind. Ultraviolet intercepts HTTP requests with a service worker, while adhering to the TompHTTP specifications and is a lead

Published April 19, 2024
Malware

Indetectables Toolkit – A Toolkit for Reversing, Malware Analysis, and Cracking

This tool compilation is carefully crafted to be useful both for beginners and veterans of the malware analysis world. It has also proven useful for people trying their luck at the cracking underworld. It’s the ideal complement to be used with the manuals from the site, and to play with the numbered

Published April 18, 2024
AI

Morphic – An AI-powered answer engine with a generative UI.

It is an AI-powered answer engine with a generative UI. Stack App framework: Next.js Text streaming / Generative UI: Vercel AI SDK Generative Model: OpenAI Search API: Tavily AI Component library: shadcn/ui Headless component primitives: Radix UI Styling: Tailwind CSS 🚀 Quickstart 1. Fork and Clone

Published April 9, 2024
Exploits

Xzbot: Exploit Demo for the xz backdoor (CVE-2024-3094)

Exploration of the xz backdoor (CVE-2024-3094). Includes the following: honeypot: fake vulnerable server to detect exploit attempts ed448 patch: patch liblzma.so to use our own ED448 public key backdoor format: format of the backdoor payload backdoor demo: cli to trigger the RCE assuming knowledge o

Published April 1, 2024
AI

OpenUI – Next-Gen Tool for Building Powerful Applications

OpenUI aims to make the process fun, fast, and flexible. It lets users describe UI using their imagination, and then see it rendered live. You can ask for changes and convert HTML to React, Svelte, Web Components, etc. It’s like v0 but open source and not as polished 😝. Running Locally You can also

Published March 30, 2024
Bluetooth

BlueSpy – Tool to Record Audio from a Bluetooth Device

BlueSpy BlueSpy was developed to record and replay audio from a Bluetooth device without the legitimate user’s awareness. The PoC was demonstrated during the talk BSAM: Seguridad en Bluetooth at RootedCON 2024 in Madrid. It’s designed to raise awareness about the insecure use of Bluetooth devices, a

Published March 22, 2024
Domain

Web-Check – Comprehensive, on-demand open source intelligence for any website

Web-Check is a powerful all-in-one tool for discovering information about a website/host. The core philosophy is simple: feed Web-Check a URL and let it gather, collate, and present a broad array of open data for you to delve into. The report shines a spotlight onto potential attack vectors, existin

Published January 14, 2024
Network

SSH-Snake: Automated SSH-Based Network Traversal

🐍 SSH-Snake is a powerful tool designed to perform automatic network traversal using SSH private keys discovered on systems, to create a comprehensive map of a network and its dependencies, identifying to what extent a network can be compromised using SSH and SSH private keys starting from a partic

Published January 14, 2024
Automation

WebCopilot – An automation tool for XSS, SQLi, LFI, SSRF and RCE

──────▄▀▄─────▄▀▄ ─────▄█░░▀▀▀▀▀░░█▄ ─▄▄──█░░░░░░░░░░░█──▄▄ █▄▄█─█░░▀░░┬░░▀░░█─█▄▄█ ██╗░░░░░░░██╗███████╗██████╗░░█████╗░░█████╗░██████╗░██╗██╗░░░░░░█████╗░████████╗░██║░░██╗░░██║██╔════╝██╔══██╗██╔══██╗██╔══██╗██╔══██╗██║██║░░░░░██╔══██╗╚══██╔══╝░╚██╗████╗██╔╝█████╗░░██████╦╝██║░░╚═╝██║░░██║██████╔

Published January 14, 2024
Exploits

Exploit Released for VMware Aria Operations for Networks RCE (CVE-2023-20887) Bug

A group of researchers has unveiled a proof-of-concept (PoC) demonstration for a serious Remote Code Execution (RCE) vulnerability present in VMware’s Aria Operations for Networks. This software suite is commonly utilized by large-scale networks, making the potential impact of this vulnerability qui

Published June 14, 2023
Windows

Windows DHCP Remote Code Execution Vulnerability (CVE-2023-28231)

Dynamic Host Configuration Protocol (DHCP) is a client/server protocol that automatically provides an Internet Protocol (IP) host with its IP address and other related configuration information, such as subnet mask and default gateway. RFCs 2131 and 2132 define DHCP as an Internet Engineering Task F

Published April 12, 2023
Forensic Tool

teler : Real-time HTTP Intrusion Detection

Teler is a real-time intrusion detection and threat alert based on a weblog that runs in a terminal with resources that we collect and provide by the community. ❤️ Features Real-time: Analyze logs and identify suspicious activity in real time. Alerting: teler provides alerting when a threat is detec

Published December 4, 2022
Script

OpenAI Chat GPT Google Chrome Extension

Chrome Extension that Integrates ChatGPT (Unofficial) into Google Search. Prerequisites Unofficial ChatGPT API Chrome Extension Installation Clone this repository Go to chrome://extensions/ Enable Developer Mode Click on Load Unpacked Select the folder where you cloned this repository Usage Make sur

Published December 4, 2022
BugBounty

APTRS – An Automated Penetration Testing Reporting System

APTRS (Automated Penetration Testing Reporting System) is an automated reporting tool in Python and Django. The tool allows Penetration testers to create a report directly without using the Traditional Docx file. It also provides an approach to keeping track of the projects and vulnerabilities. Prer

Published November 24, 2022
Forensic Tool

INTLog – A Flask app to Track Interesting Artifacts during an Investigation

INTLog is a simple Flask app designed to keep track of potentially interesting artifacts during an investigation. This application was designed to keep track of artifacts that you may stumble across during an investigation. This project is in an EXTREMELY early stage. Setup Setup env: INTLog » pytho

Published November 24, 2022
Reconnaissance

EmailAll – A powerful Email Collect tool

EmailAllis a powerful Email Collect tool —— a powerful email collection tool. Installation $ git clone https://github.com/Taonn/EmailAll.git $ cd EmailAll $ pip3 install -r requirements.txt EmailAll is a powerful Email Collect tool Example: python3 emailall.py check python3 emailall.py –domain examp

Published November 24, 2022
Post Exploitation

DonPAPI : Dumping DPAPI Credential Remotely

Dumping relevant information on compromised targets without AV detection. DPAPI dumping Lots of credentials are protected by DPAPI. We aim at locating those “secured” credentials, and retrieve them using : User Password Domaine DPAPI BackupKey Local machine DPAPI Key (protecting TaskScheduled blob)

Published November 22, 2022
AWS

AWSGoat : A Damn Vulnerable AWS Infrastructure

Compromising an organization’s cloud infrastructure is like sitting on a gold mine for attackers. And sometimes, a simple misconfiguration or a vulnerability in web applications, is all an attacker needs to compromise the entire infrastructure. Since the cloud is relatively new, many developers are

Published November 22, 2022
OSITN

Custom Processing Unit – Framework to Hook, Patch and Trace CPU Microcode

Custom Processing Unit is the first dynamic analysis framework able to hook, patch, and trace CPU microcode at the software level. It works by leveraging undocumented instructions in Intel CPUs that allow access to the CRBUS. Using our microcode decompiler we reverse-engineered how the CPU uses the

Published August 12, 2022
GitHub

Vulnerable Spring Framework Application for Testing Spring4Shell

This application is intentionally built for testing Remote Code Execution on Spring Core aka Spring4Shell. How do I use this? First, this was tested on Ubuntu 21.04 (because I hate myself) and OpenJDK 11. Once you’ve accepted that, snag the code and build it. git clone https://github.com/jbaines-r7/

Published March 31, 2022
Uncategorized

DirtyPipe for Android – Root Exploit for Pixel 6

Dirty Pipe (CVE-2022-0847) temporary root PoC for Android. Currently, this exploit run on Pixel 6 only with security patch level 2022-02-05. Don’t use on other devices or other versions. It may damage your device. Use it at your own risk, we are not responsible for any damage caused How to use Downl

Published March 24, 2022
BugBounty

httpx – multi-purpose HTTP toolkit

httpx is a fast and multi-purpose HTTP toolkit allows to run of multiple probers using retryablehttp library, it is designed to maintain the result reliability with increased threads. Features Simple and modular codebase making it easy to contribute. Fast And fully configurable flags to probe multip

Published December 1, 2021
BugBounty

XORpass – An encoder to bypass WAF

XORpass is an encoder to bypass WAF filters using XOR operations. Installation & Usage git clone https://github.com/devploit/XORpasscd XORpass$ python3 xorpass.py -h Example of bypass: Using clear PHP function: Using XOR bypass of that function: $ python3 xorpass.py -e “system(ls)” Why does PHP trea

Published November 8, 2021
Tools

Commix – Automatic Command Injection Exploiter Tool

Commix (short for [comm]and [i]njection e[x]ploiter) is an open-source penetration testing tool, written by Anastasios Stasinopoulos (@ancst), that automates the detection and exploitation of command injection vulnerabilities. Installation You can download commix on any platform by cloning the offic

Published October 20, 2021
Android

Mariana Trench: Tool to test Android App

Mariana Trench is a security-focused static analysis platform targeting Android. This guide will walk you through setting up Mariana Trench on your machine and get you to find your first remote code execution vulnerability in a small sample app. Prerequisites Mariana Trench requires a recent version

Published September 30, 2021
Linux

PwnLnX – Advanced Python Reverse Shell for Hacking

An advanced multi-threaded, multi-client python reverse shell for hacking Linux systems. There’s still more work to do so feel free to help out with the development. Disclaimer: This reverse shell should only be used in the lawful, remote administration of authorized systems. Accessing a computer ne

Published September 24, 2021
Bug Finder

Kubescape – Manage Kubernetes Security

Kubescape is the first tool for testing if Kubernetes is deployed securely as defined in Kubernetes Hardening Guidance by NSA and CISA Use Kubescape to test clusters or scan single YAML files and integrate it to your processes. Install curl -s https://raw.githubusercontent.com/armosec/kubescape/mast

Published September 21, 2021
Tools

LibAFL, the fuzzer library

Advanced Fuzzing Library – Slot your own fuzzers together and extend their features using Rust. LibAFL is written and maintained by Andrea Fioraldi andreafioraldi@gmail.com and Dominik Maier mail@dmnk.co. LibAFL is a collection of reusable pieces of fuzzers, written in Rust. It is fast, multi-platfo

Published July 22, 2021
Forensic Tool

Mobile Verification Toolkit For Pegasus Infection

Mobile Verification Toolkit (MVT) is a collection of utilities to simplify and automate the process of gathering forensic traces helpful to identify a potential compromise of Android and iOS devices. It has been developed and released by the Amnesty International Security Lab in July 2021 in the con

Published July 21, 2021
Exploits

HiveNightmare aka CVE-2021–36934

A zero-day exploit for HiveNightmare, which allows you to retrieve all registry hives in Windows 10 as a non-administrator user. For example, this includes hashes in SAM, which can be used to execute code as SYSTEM. How does this work? The permissions on key registry hives are set to allow all non-a

Published July 21, 2021
Burp Suite

Download Burp Suite 2021.6

This release includes the following bug fixes. Playing back recorded login sequences is now more reliable when one of the elements in the series is hidden by other elements on the page. Recorded login sequences can now be tested correctly when you play them from the configuration library. Changes to

Published May 26, 2021
GitHub

Profil3r – Profiles of a Person on Social Networks

Profil3r is an OSINT tool that allows you to find potential profiles of a person on social networks, as well as their email addresses. This program also alerts you to the presence of a data leak for the found emails. 💡 Prerequisite Python 3 Installation Install PyInquirer, jinja2 and bs4 : pip3 ins

Published May 23, 2021
GitHub

Winbindex – The Windows Binaries Index

An index of Windows binaries, including download links for executables such as exe, dll and sys files. All linked binary files are hosted on the Microsoft public symbol server (msdl.microsoft.com), Winbindex merely indexes metadata that enables to generate those links. The website, along with the wh

Published May 23, 2021
Burp Suite

Download Burp Suite 2021.5.1

What’s new in Burp Suite 2021.5.1 We have updated Burp Suite’s embedded browser to Chromium version 90.0.4430.212, which fixes several security issues that Google has classified as high. Bug fix: Payload processing rules that invoke extensions now display correctly. Windows Linux Jar Mac Burp Suite

Published May 22, 2021
GitHub

Routopsy – Tool to Hijack Network Routes

Routopsy is a toolkit built to attack often overlooked networking protocols. Routopsy currently supports attacks against Dynamic Routing Protocols (DRP) and First-Hop Redundancy Protocols (FHRP). Most of the attacks currently implemented make use of a weaponised ‘virtual router’ as opposed to implem

Published August 10, 2020
Uncategorized

OWASP Mobile Security Testing Guide (MSTG).

The OWASP Mobile Security Testing Guide (MSTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the controls listed in the OWASP Mobile Application Verification Standard (MASVS). You can also read the MSTG on Gitbook or

Published April 10, 2020
Exploits

Nexus Repository Manager CVE-2020-10199/10204

Nexus Repository Manager OSS/Pro: <=3.21.1 Nexus Repository Manager 3.21.1 http/s:/help.sonatype.com/repomanager3/download/ Nexus POCE Exploit https//github.com/wsfengfan/CVE-2020-10199-10204 Usage:python3 poc.py -i 127.0.0.1 -p 8081 -c cookie -csrf csrf-token 1), CVE-2020-10204 Manual verification

Published April 8, 2020
Linux

pspy tool – Monitor linux processes without root permissions

pspy – unprivileged Linux process snooping pspy is a command line tool designed to snoop on processes without need for root permissions. It allows you to see commands run by other users, cron jobs, etc. as they execute. Great for enumeration of Linux systems in CTFs. Also great to demonstrate your c

Published April 3, 2020
Linux

Programming Linux Anti-Reversing Techniques

Programming Linux Anti-Reversing Techniques teaches the reader how to code and analyze well known anti-reversing techniques for Linux. The book shows how a reverse engineer analyzes a binary using tools like IDA, Radare2, GDB, readelf, and more. The code is presented to the reader ready to compile a

Published April 1, 2020
Bug Finder

Scanners Box : A Powerful Hackers Tool

Scanners Box also known as scanbox, is a powerful hacker toolkit, which collects more than 10 categories of open source scanners from Github, including subdomain, database, middleware and other modular design scanner etc. But for other Well-known scanning tools, such as nmap, w3af, brakeman, arachni

Published June 3, 2019
Uncategorized

Server-side Request Forgery Detector

This is the application source code for the SSRF Detector website. The website has been EOL as of April 7th 2017, but the code has been updated to be run on a local machine. This documentation is a little touch-and-go as there is a lot of configuration for Nginx, SSL, etc… but for a local … Read mor

Published June 3, 2019
Uncategorized

Gorsair – Penetration Testing tool for Docker

Gorsair is a penetration testing tool for discovering and remotely accessing Docker APIs from vulnerable Docker containers. Once it has access to the docker daemon, you can use Gorsair to directly execute commands on remote containers. Exposing the docker API on the internet is a tremendous risk, as

Published February 12, 2019
Tools

Hash Generator & Cracker Online Offline

#Install Note Clone the repository: git clone https://github.com/0xR0/hediye.git #Then go inside: cd hediye/ #use examples: python3 hediye.py -k Key / For –> Generate Hash (md5, sha1, sha224, sha256, sha384, sha512) python3 hediye.py -v HASH -f Wordlist / For –> Brute Force Attack (md5, sha1, sha224

Published January 10, 2019
Android

PHANTOM EVASION 2.0.1- An Antivirus Evasion Tool

Phantom-Evasion is an interactive antivirus evasion tool written in python capable to generate (almost) FUD executable even with the most common 32 bit msfvenom payload (lower detection ratio with 64 bit payloads). The aim of this tool is to make antivirus evasion an easy task for pentesters through

Published January 2, 2019
Bug Finder

XSShell – A XSS Reverse Shell Framework

XSShell is a cross-site-scripting reverse shell… Okay, well maybe it’s not a true reverse shell, but it will allow you to interact in real time with an XSS victim’s browser. XSShell also comes with a number of premade XSS payloads to use: alert – send a js alert message cs – get cookies and any … Re

Published November 28, 2018
GitHub

Zstandard – Fast real-time compression algorithm

Zstandard, or zstd as short version, is a fast lossless compression algorithm, targeting real-time compression scenarios at zlib-level and better compression ratios. It’s backed by a very fast entropy stage, provided by Huff0 and FSE library. The project is provided as an open-source dual BSD and GP

Published November 26, 2018
Network

CloudBunny : Capture Real IP of Server behind WAF

CloudBunny is a tool to capture the origin server that uses a WAF as a proxy or protection. This tool we used three search engines to search domain information: Shodan, Censys and Zoomeye. To use the tools you need the API Keys, you can pick up the following links: Shodan – https://account.shodan.io

Published November 17, 2018
Exploits

FakeImageExploiter – Use a Fake Image to Exploit Target

This module takes one existing image.jpg and one payload.ps1 (input by user) and builds a new payload (agent.jpg.exe) that if executed it will trigger the download of the 2 previous files stored into apache2 (image.jpg + payload.ps1) and execute them. This module also changes the agent.exe Icon to m

Published November 14, 2018
Forensic Tool

DFIRTrack: (Digital Forensics and Incident Response Tracking application

DFIRTrack (Digital Forensics and Incident Response Tracking application) is an open source web application mainly based on Djangousing a PostgreSQL database backend. In contrast to other great incident response tools, which are mainly case-based and support the work of CERTs, SOCs etc. in their dail

Published November 13, 2018
Android

DROID-HUNTER – Android Pentesting Tool

Android application vulnerability analysis and Android pentest tool A. Support> App info check> Baksmaling android app> Decompile android app> Extract class file> Extract java code> Pattern base Information Leakage 2. How to Install?A. Download(clone) & Unpack DROID-HUNTER git clone https://github.c

Published September 7, 2018
Java

HackBar (Burpsuite Plugin)

RequirementsBurpsuiteJavaInstall Plugin Download Jar https://github.com/d3vilbug/HackBar/releases and add in burpsuite Tested on Burpsuite 1.7.36 Windows 7/8.1/10 Kali linux (2013.3) DOWNLOAD

Published September 6, 2018
Tools

Step: A tool to Make Work easier for zero trust technologies

Step is a zero trust swiss army knife. It’s an easy-to-use and hard-to-misuse utility for building, operating, and automating systems that use zero trust technologies like authenticated encryption (X.509, TLS), single sign-on (OAuth OIDC, SAML), multi-factor authentication (OATH OTP, FIDO U2F), encr

Published August 8, 2018
Post Exploitation

p0wnedShell : Post Exploitation Toolkit

p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploi

Published August 8, 2018
Post Exploitation

Bashark – Post exploitation toolkit

Introduction Bashark aids pentesters and security researchers during the post-exploitation phase of security audits. Usage To launch Bashark on compromised host, simply source the bashark.sh script from terminal: $ source bashark.sh Then type help to see Bashark’s help menu Features Single Bash scri

Published August 6, 2018
GitHub

Repo Security Scanner – Search secrets from GitHub

repo-security-scanner CLI tool that finds secrets accidentally committed to a git repo, eg passwords, private keys Run it against your entire repo’s history by piping the output from git log -p Installation Download the latest stable release of the CLI tool for your architecture Extract the tar and

Published August 6, 2018
Forensic Tool

Stegextract: Extract Hidden files and strings from Images.

Description Stegextract extracts any trailing data after the image’s closing bytes, and any hidden files (or other images) embedded within the image. Short byte combinations such as JPEG’s FFD8 FFE0 might sometimes create false positives. Manually reviewing the hexdump is sometimes inevitable in cas

Published July 29, 2018
Pentester

Raccoon: Tool for Reconnaissance and Information Gathering

Features DNS details DNS visual mapping using DNS dumpster WHOIS information TLS Data – supported ciphers, TLS versions, certificate details and SANs Port Scan Services and scripts scan URL fuzzing and dir/file detection Subdomain enumeration – uses Google dorking, DNS dumpster queries, SAN discover

Published July 29, 2018
Reconnaissance

Photon: Fast web crawler for Recon

Photon is a lightning fast web crawler which extracts URLs, files, intel & endpoints from a target. Usage -u –url Run Photon against a single website. python photon.py -u http://example.com Specifying a URL with it’s schema i.e. http(s):// is optional but you must add www. if the website has it. Tip

Published July 24, 2018
Reconnaissance

WAScan – Web Application Scanner

WAScan ((W)eb (A)pplication (Scan)ner) is a Open Source web application security scanner. It is designed to find various vulnerabilities using “black-box” method, that means it won’t study the source code of web applications but will work like a fuzzer, scanning the pages of the deployed web applica

Published June 22, 2018
BugBounty

Takeover – SubDomain TakeOver Vulnerability Scanner

Sub-domain takeover vulnerability occur when a sub-domain (subdomain.example.com) is pointing to a service (e.g: GitHub, AWS/S3,..) that has been removed or deleted. This allows an attacker to set up a page on the service that was being used and point their page to that sub-domain. For example, if s

Published June 22, 2018
BugBounty

SubFinder – Powerfull Sub-domain Enumeration Tool

SubFinder is a subdomain discovery tool that uses various techniques to discover massive amounts of subdomains for any target. It has been aimed as a successor to the sublist3r project. SubFinder uses Passive Sources, Search Engines, Pastebins, Internet Archives, etc to find subdomains and then it u

Published June 22, 2018
BugBounty

SubOver – Subdomain Takeover Tool

Subover is a Hostile Subdomain Takeover tool originally written in python but rewritten from scratch in Golang. Since it’s redesign, it has been aimed with speed and efficiency in mind. Till date, SubOver detects 30+ services which is much more than any other tool out there. The tool uses Golang con

Published June 22, 2018
Network

SandMap: Network and System Reconnaissance using Nmap engine.

Sandmap is a tool supporting network and system reconnaissance using the massive Nmap engine. It provides a user-friendly interface, automates and speeds up scanning and allows you to easily use many advanced scanning techniques. Key Features simple CLI with the ability to run pure Nmap engine prede

Published June 22, 2018
Android

Droid Application Fuzz Framework

Droid Application Fuzz Framework (DAFF) helps you to fuzz Android Browsers and PDF Readers for memory corruption bugs in real android devices. You can use the inbuilt fuzzers or import fuzz files from your own custom fuzzers. DAFF consist of inbuilt fuzzers and crash monitor. It currently supports f

Published March 8, 2018
Linux

KRACK Detector: Know KRACK Attack on Your Network

KRACK Detector is a Python script to detect possible KRACK attacks against client devices on your network. The script is meant to be run on the Access Point rather than the client devices. It listens on the Wi-Fi interface and waits for duplicate message 3 of the 4-way handshake. It then disconnects

Published October 23, 2017
Tools

Official Black Hat Arsenal Tools Github Repository

This github account maps to the Black Hat Arsenal tools since its inception in 2011. For readibility, the tools are classified by category and not by session. This account is maintained by ToolsWatch.orgthe official organizer of the Black Hat Arsenal event Disclaimer: Tools not demonstrated during a

Published October 21, 2017
Apple

Steel.Password- Easily get Apple users ID’s

Do you want the user’s Apple ID password, to get access to their Apple account, or to try the same email/password combination on different web services? Just ask your users politely, they’ll probably just hand over their credentials, as they’re trained to do so 👌 iOS asks the user for their iTunes

Published October 11, 2017
Android

Hijacker v1.3- WiFi Hacking Tool for Android

Hijacker is a Graphical User Interface for the penetration testing tools Aircrack-ng, Airodump-ng, MDK3 and Reaver. It offers a simple and easy UI to use these tools without typing commands in a console and copy&pasting MAC addresses. This application requires an ARM android device with a wireless a

Published September 27, 2017
Android

Radare2- Debug Windows apps in Linux and Mac

r2 is a rewrite from scratch of radare in order to provide a set of libraries and tools to work with binary files. Radare project started as a forensics tool, a scriptable commandline hexadecimal editor able to open disk files, but later support for analyzing binaries, disassembling code, debugging

Published September 27, 2017
Pentester

XSStrike: Fuzz, Crawl and Bruteforce Parameters for XSS

XSStrike is a python script designed to detect and exploit XSS vulnerabilites. Visit XSStrike’s project site for more info. A list of features XSStrike has to offer: Fuzzes a parameter and builds a suitable payload Bruteforces paramteres with payloads Has an inbuilt crawler like functionality Can re

Published August 4, 2017
Hash Cracker

Hash Buster – scraps online hash crackers to find cleartext of a hash

Hash Buster – scraps online hash crackers to find cleartext of a hash Hash Buster is a python script which uses several online hash crackers to find cleartext of a hash in less than 5 seconds. Features of Hash Buster: Detects hash MD5 Support SHA1 Support SHA2 Support Adding more APIs for SHA1 and S

Published August 4, 2017
Pentester

InforFinder – tool to collect information of any domains pointing at some server

InforFinder – tool to collect information of any domains pointing at some server. Inforfinder is a tool made to collect information of any domain pointing at a server (ip,domain,range,file). Requires python libs: pyRequests and pyDNS -First, you need to install complementary libraries: user@machine$

Published August 4, 2017
Android

Hijacker-Wireless Auditing Tool for Android

Hijacker is a Graphical User Interface for the wireless auditing tools airodump-ng, aireplay-ng and mdk3. It offers a simple and easy UI to use these tools without typing commands in a console and copy&pasting MAC addresses. This application requires an android device with a wireless adapter that su

Published January 2, 2017
Network

ZoomEye- A Cyber Space Search Engine

ZoomEye is another cool web search engine, where users can search for the connected devices, ports and other things which helps to understand the network infrastructure for Pentest. Below image shows the shortcuts or keys to help for better search Check it Here

Published January 2, 2017
Firewall

Morpheus – automated ettercap TCP/IP Hijacking tool

Version release : v1.7-Alpha Author : pedro ubuntu [ r00t-3xp10it ] Distros Supported : Linux Ubuntu, Kali, Mint, Parrot OS Suspicious-Shell-Activity (SSA) RedTeam develop @2016 LEGAL DISCLAMER The author does not hold any responsibility for the bad use of this tool, remember that attacking targets

Published December 14, 2016
Bug Finder

Lynis 2.2.0 – Security Auditing Tool for Unix/Linux Systems

Lynis is an open source security auditing tool. Commonly used by system administrators, security professionals and auditors, to evaluate the security defenses of their Linux/Unix based systems. It runs on the host itself, so it can perform very extensive security scans. Supported operating systems T

Published March 21, 2016
Uncategorized

Mobile-Security-Framework (MobSF) for Android and iOS

Mobile Security Framework (MobSF) is an intelligent, all-in-one open source mobile application (Android/iOS) automated pen-testing framework capable of performing static and dynamic analysis. It can be used for effective and fast security analysis of Android and iOS Applications and supports both bi

Published March 15, 2016
Joomla

Project Arsenal X – As HackTheGame But Real

Project Arsenal X New version of my Arsenal X written in Delphi with the following options: [+] Gmail Inbox [+] Whois Client [+] Table [+] Downloader [+] Get IP [+] Locate IP [+] K0bra SQLI Scanner [+] Crack multiple hashes [+] Search admin panel [+] Port Scanner [+] Multi Cracker with support for F

Published January 17, 2016
Android

Kali NetHunter 3.0 – Android Mobile Penetration Testing Platform

What’s New in Kali NetHunter 3.0 NetHunter Android Application Rewrite The NetHunter Android application has been totally redone and has become much more “application centric”. Many new features and attacks have been added, not to mention a whole bunch of community-driven bug fixes. The NetHunter ap

Published January 7, 2016
Linux

Phpsploit – Stealth Post-Exploitation Framework

PhpSploit is a remote control framework, aiming to provide a stealth interactive shell-like connection over HTTP between client and web server. It is a post-exploitation tool capable to maintain access to a compromised web server for privilege escalationpurposes. Overview The obfuscated communicatio

Published January 4, 2016
Joomla

Joomlavs – A Black Box, Joomla Vulnerability Scanner

JoomlaVS is a Ruby application that can help automate assessing how vulnerable a Joomla installation is to exploitation. It supports basic finger printing and can scan for vulnerabilities in components, modules and templates as well as vulnerabilities that exist within Joomla itself. How to install

Published January 3, 2016
Linux

Blade – A Webshell Connection Tool With Customized WAF Bypass Payloads

Blade is a webshell connection tool based on console, currently under development and aims to be a choice of replacement of Chooper (中国菜刀). Chooper is a very cool webshell client with widly typies of server side scripts supported, but Chooper can only work on Windows opreation system, so this is the

Published January 2, 2016
Linux

Nipe – Script To Redirect All Traffic From The Machine To The Tor Network

Script to redirect all the traffic from the machine to the Tor network. [+] AUTOR: Vinicius Gouvea [+] EMAIL: vini@inploit.com [+] BLOG: https://medium.com/viniciusgouvea [+] GITHUB: https://github.com/HeitorG [+] FACEBOOK: https://fb.com/viniciushgouvea Installing: git clone https://github.com/Heit

Published January 2, 2016
Linux

Sublist3R – Fast Subdomains Enumeration Tool For Penetration Testers

Sublist3r is python tool that is designed to enumerate subdomains of websites using search engines. It helps penetration testers and bug hunters collect and gather subdomains for the domain they are targeting. Sublist3r currently supports the following search engines: Google, Yahoo, Bing, Baidu, and

Published January 2, 2016
Bug Finder

Mosca – Static Analysis Tool To Find Bugs

Just another Simple static analysis tool to find bugs like a grep unix command, at mosca have a modules, that was call egg, each egg is a simple config to find bug at especific language like PHP,Ruby,ASP etc… Example of egg config at directory “egg”, If Mosca read a line with vunerability of egg in

Published January 2, 2016
SQLinjection

jSQL Injection v0.73 – Java Tool For Automatic SQL Database Injection

jSQL Injection is a lightweight application used to find database information from a distant server. jSQL is free, open source and cross-platform (Windows, Linux, Mac OS X, Solaris). jSQL is part of Kali Linux, the official new BackTrack penetration distribution. jSQL is also included in Black Hat S

Published January 2, 2016