Blog
Analysis, explainers and methodology notes. Articles are published in WordPress and rendered here at build time — their URLs are unchanged.
All posts
WP2Shell Vulnerability Checker – Test Your WordPress in Seconds
Check your WordPress site vulnerable to WP2Shell. Instant version checker, patch steps, WAF rules, detection scripts and IOCs for CVE-2026-63030 / CVE-2026-60137.
UncategorizedT3MP3ST — Autonomous Red Teaming Platform
A multi-agent offensive-security framework, built to turn the AI coding agent you already run into a zero-day hunter.
Revers EngineeringSightHouse: Automated Function Identification for Reverse Engineering
SightHouse is an open-source tool developed by Quarkslab that helps reverse engineers automatically identify known functions inside binaries by matching them with previously analyzed code. SightHouse is a tool designed to assist reverse engineers by retrieving information and metadata from programs
AICISO Assistant — One-stop GRC Platform for Risk Management, AppSec
CISO Assistant offers a fresh perspective on Cybersecurity Management and GRC (Governance, Risk, and Compliance) practices: Features Upcoming features are listed on the roadmap. CISO Assistant is developed and maintained by Intuitem, a company specializing in Cybersecurity, Cloud, and Data/AI. Core
AndroidAndroHunter – Android Security Research Toolkit
AndroHunter is a native Android application that provides a full suite of mobile security testing tools — all running directly on the device without requiring a rooted phone for most features. It is designed for security researchers participating in bug bounty programs (HackerOne, Yes We Hack, Intig
OSINTWhatsApp Activity Tracker – Track WhatsApp by Phone Number
This project implements the research from the paper “Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant Messengers” by Gabriel K. Gegenhuber, Maximilian Günther, Markus Maier, Aljosha Judmayer, Florian Holzbauer, Philipp É. Frenzel, and Johanna Ullrich (Universi
UncategorizedUsername Finder
PythonPyXL – Python Directly in Hardware
What is PyXL? PyXL is a custom hardware processor that executes Python directly — no interpreter, no JIT, and no tricks. It takes regular Python code and runs it in silicon. A custom toolchain compiles a .py file into CPython ByteCode, translates it to a custom assembly, and produces a binary that r
OSINTCF-Hero : Find Real IP Behind Cloudflare
CF-Hero is a comprehensive reconnaissance tool developed to discover the real IP addresses of web applications protected by Cloudflare. It gathers multi-source intelligence through various methods. DNS Reconnaissance Current DNS records (A, TXT) Historical DNS data analysis Associated domain discove
BugBountyHExHTTP – HTTP Header Exploitation Tool
HExHTTP is a tool designed to perform tests on HTTP headers and analyze the results to identify vulnerabilities and interesting behaviors. Features Server Error response checking Localhost header response analysis Vhosts checking Methods response analysis HTTP Version analysis [Experimental] Cache P
AuthHanko – An Authentication and User Management Solution for the Passkey
Hanko is an open-source authentication and user management solution with a focus on moving the login beyond passwords while being 100% deployable today. Supports all modern authentication methods, incl. passkeys, social logins, and SAML SSO Highly flexible configuration options (e.g. optional/user-d
Social MediaPostiz – Free AI Social Media Scheduling Tool
Postiz: An alternative to: Buffer.com, Hypefury, Twitter Hunter, Etc… Postiz offers everything you need to manage your social media posts, build an audience, capture leads, and grow your business. Intro Schedule all your social media posts (many AI features) Measure your work with analytics. Collabo
OSINTMaigret – Search Person by Username from Thousands of Sites
Maigret collects a dossier on a person by username only, checks for accounts on many sites, and gathers all the available information from web pages. No API keys are required. Maigret is an easy-to-use and powerful fork of Sherlock. Currently supports more than 3000 sites (full list), search is laun
Forensic ToolLogicytics: System Data Harvester
Logicytics is a cutting-edge tool designed to meticulously harvest and collect a vast array of Windows system data for forensic analysis. Crafted with Python 🐍, it’s an actively developed project that is dedicated to gathering as much sensitive data as possible and packaging it neatly into a ZIP fi
AIDubbie – Open-source AI video dubbing studio
Dubbie is an open-source AI dubbing studio that costs $0.1/min, which is about ~20x less than alternatives like ElevenLabs, RaskAI, or Speechify. While still in early development and not at feature parity with these alternatives, Dubbie offers enough features to create dubs for basic videos. What is
ScriptHamster Kombat: Auto Clicker and Desktop Version
Everyone is now familiar with the trending telegram-based crypto game name Hamster Kombat, a game that blends adorable critters with the world of cryptocurrency, which is taking the internet by storm. This Telegram-based game has rocketed to popularity, boasting over 200 million users in a shockingl
ToolsGWPSan: Sampling-Based Sanitizer Framework
GWPSan is a framework for low-overhead sampling-based dynamic binary instrumentation, designed for implementing various bug detectors (also called “sanitizers”) suitable for production uses. GWPSan does not modify the executed code, but instead performs dynamic analysis from signal handlers. Usage T
AIAgentic Security – LLM Security Scanner
Features Customizable Rule Sets or Agent based attacks🛠️ Comprehensive fuzzing for any LLMs 🧪 LLM API integration and stress testing 🛠️ Wide range of fuzzing and attack techniques 🌀 Note: Please be aware that Agentic Security is designed as a safety scanner tool and not a foolproof solution. It
UncategorizedHow to Make an Ultraviolet Proxy
Ultraviolet is a highly advanced web proxy used for evading internet censorship or accessing websites in a controlled sandbox. It is designed with security and performance in mind. Ultraviolet intercepts HTTP requests with a service worker, while adhering to the TompHTTP specifications and is a lead
MalwareIndetectables Toolkit – A Toolkit for Reversing, Malware Analysis, and Cracking
This tool compilation is carefully crafted to be useful both for beginners and veterans of the malware analysis world. It has also proven useful for people trying their luck at the cracking underworld. It’s the ideal complement to be used with the manuals from the site, and to play with the numbered
AIMorphic – An AI-powered answer engine with a generative UI.
It is an AI-powered answer engine with a generative UI. Stack App framework: Next.js Text streaming / Generative UI: Vercel AI SDK Generative Model: OpenAI Search API: Tavily AI Component library: shadcn/ui Headless component primitives: Radix UI Styling: Tailwind CSS 🚀 Quickstart 1. Fork and Clone
ExploitsXzbot: Exploit Demo for the xz backdoor (CVE-2024-3094)
Exploration of the xz backdoor (CVE-2024-3094). Includes the following: honeypot: fake vulnerable server to detect exploit attempts ed448 patch: patch liblzma.so to use our own ED448 public key backdoor format: format of the backdoor payload backdoor demo: cli to trigger the RCE assuming knowledge o
AIOpenUI – Next-Gen Tool for Building Powerful Applications
OpenUI aims to make the process fun, fast, and flexible. It lets users describe UI using their imagination, and then see it rendered live. You can ask for changes and convert HTML to React, Svelte, Web Components, etc. It’s like v0 but open source and not as polished 😝. Running Locally You can also
BluetoothBlueSpy – Tool to Record Audio from a Bluetooth Device
BlueSpy BlueSpy was developed to record and replay audio from a Bluetooth device without the legitimate user’s awareness. The PoC was demonstrated during the talk BSAM: Seguridad en Bluetooth at RootedCON 2024 in Madrid. It’s designed to raise awareness about the insecure use of Bluetooth devices, a
DomainWeb-Check – Comprehensive, on-demand open source intelligence for any website
Web-Check is a powerful all-in-one tool for discovering information about a website/host. The core philosophy is simple: feed Web-Check a URL and let it gather, collate, and present a broad array of open data for you to delve into. The report shines a spotlight onto potential attack vectors, existin
NetworkSSH-Snake: Automated SSH-Based Network Traversal
🐍 SSH-Snake is a powerful tool designed to perform automatic network traversal using SSH private keys discovered on systems, to create a comprehensive map of a network and its dependencies, identifying to what extent a network can be compromised using SSH and SSH private keys starting from a partic
AutomationWebCopilot – An automation tool for XSS, SQLi, LFI, SSRF and RCE
──────▄▀▄─────▄▀▄ ─────▄█░░▀▀▀▀▀░░█▄ ─▄▄──█░░░░░░░░░░░█──▄▄ █▄▄█─█░░▀░░┬░░▀░░█─█▄▄█ ██╗░░░░░░░██╗███████╗██████╗░░█████╗░░█████╗░██████╗░██╗██╗░░░░░░█████╗░████████╗░██║░░██╗░░██║██╔════╝██╔══██╗██╔══██╗██╔══██╗██╔══██╗██║██║░░░░░██╔══██╗╚══██╔══╝░╚██╗████╗██╔╝█████╗░░██████╦╝██║░░╚═╝██║░░██║██████╔
ExploitsExploit Released for VMware Aria Operations for Networks RCE (CVE-2023-20887) Bug
A group of researchers has unveiled a proof-of-concept (PoC) demonstration for a serious Remote Code Execution (RCE) vulnerability present in VMware’s Aria Operations for Networks. This software suite is commonly utilized by large-scale networks, making the potential impact of this vulnerability qui
WindowsWindows DHCP Remote Code Execution Vulnerability (CVE-2023-28231)
Dynamic Host Configuration Protocol (DHCP) is a client/server protocol that automatically provides an Internet Protocol (IP) host with its IP address and other related configuration information, such as subnet mask and default gateway. RFCs 2131 and 2132 define DHCP as an Internet Engineering Task F
Forensic Toolteler : Real-time HTTP Intrusion Detection
Teler is a real-time intrusion detection and threat alert based on a weblog that runs in a terminal with resources that we collect and provide by the community. ❤️ Features Real-time: Analyze logs and identify suspicious activity in real time. Alerting: teler provides alerting when a threat is detec
ScriptOpenAI Chat GPT Google Chrome Extension
Chrome Extension that Integrates ChatGPT (Unofficial) into Google Search. Prerequisites Unofficial ChatGPT API Chrome Extension Installation Clone this repository Go to chrome://extensions/ Enable Developer Mode Click on Load Unpacked Select the folder where you cloned this repository Usage Make sur
BugBountyAPTRS – An Automated Penetration Testing Reporting System
APTRS (Automated Penetration Testing Reporting System) is an automated reporting tool in Python and Django. The tool allows Penetration testers to create a report directly without using the Traditional Docx file. It also provides an approach to keeping track of the projects and vulnerabilities. Prer
Forensic ToolINTLog – A Flask app to Track Interesting Artifacts during an Investigation
INTLog is a simple Flask app designed to keep track of potentially interesting artifacts during an investigation. This application was designed to keep track of artifacts that you may stumble across during an investigation. This project is in an EXTREMELY early stage. Setup Setup env: INTLog » pytho
ReconnaissanceEmailAll – A powerful Email Collect tool
EmailAllis a powerful Email Collect tool —— a powerful email collection tool. Installation $ git clone https://github.com/Taonn/EmailAll.git $ cd EmailAll $ pip3 install -r requirements.txt EmailAll is a powerful Email Collect tool Example: python3 emailall.py check python3 emailall.py –domain examp
Post ExploitationDonPAPI : Dumping DPAPI Credential Remotely
Dumping relevant information on compromised targets without AV detection. DPAPI dumping Lots of credentials are protected by DPAPI. We aim at locating those “secured” credentials, and retrieve them using : User Password Domaine DPAPI BackupKey Local machine DPAPI Key (protecting TaskScheduled blob)
AWSAWSGoat : A Damn Vulnerable AWS Infrastructure
Compromising an organization’s cloud infrastructure is like sitting on a gold mine for attackers. And sometimes, a simple misconfiguration or a vulnerability in web applications, is all an attacker needs to compromise the entire infrastructure. Since the cloud is relatively new, many developers are
OSITNCustom Processing Unit – Framework to Hook, Patch and Trace CPU Microcode
Custom Processing Unit is the first dynamic analysis framework able to hook, patch, and trace CPU microcode at the software level. It works by leveraging undocumented instructions in Intel CPUs that allow access to the CRBUS. Using our microcode decompiler we reverse-engineered how the CPU uses the
GitHubVulnerable Spring Framework Application for Testing Spring4Shell
This application is intentionally built for testing Remote Code Execution on Spring Core aka Spring4Shell. How do I use this? First, this was tested on Ubuntu 21.04 (because I hate myself) and OpenJDK 11. Once you’ve accepted that, snag the code and build it. git clone https://github.com/jbaines-r7/
UncategorizedDirtyPipe for Android – Root Exploit for Pixel 6
Dirty Pipe (CVE-2022-0847) temporary root PoC for Android. Currently, this exploit run on Pixel 6 only with security patch level 2022-02-05. Don’t use on other devices or other versions. It may damage your device. Use it at your own risk, we are not responsible for any damage caused How to use Downl
BugBountyhttpx – multi-purpose HTTP toolkit
httpx is a fast and multi-purpose HTTP toolkit allows to run of multiple probers using retryablehttp library, it is designed to maintain the result reliability with increased threads. Features Simple and modular codebase making it easy to contribute. Fast And fully configurable flags to probe multip
BugBountyXORpass – An encoder to bypass WAF
XORpass is an encoder to bypass WAF filters using XOR operations. Installation & Usage git clone https://github.com/devploit/XORpasscd XORpass$ python3 xorpass.py -h Example of bypass: Using clear PHP function: Using XOR bypass of that function: $ python3 xorpass.py -e “system(ls)” Why does PHP trea
ToolsCommix – Automatic Command Injection Exploiter Tool
Commix (short for [comm]and [i]njection e[x]ploiter) is an open-source penetration testing tool, written by Anastasios Stasinopoulos (@ancst), that automates the detection and exploitation of command injection vulnerabilities. Installation You can download commix on any platform by cloning the offic
AndroidMariana Trench: Tool to test Android App
Mariana Trench is a security-focused static analysis platform targeting Android. This guide will walk you through setting up Mariana Trench on your machine and get you to find your first remote code execution vulnerability in a small sample app. Prerequisites Mariana Trench requires a recent version
LinuxPwnLnX – Advanced Python Reverse Shell for Hacking
An advanced multi-threaded, multi-client python reverse shell for hacking Linux systems. There’s still more work to do so feel free to help out with the development. Disclaimer: This reverse shell should only be used in the lawful, remote administration of authorized systems. Accessing a computer ne
Bug FinderKubescape – Manage Kubernetes Security
Kubescape is the first tool for testing if Kubernetes is deployed securely as defined in Kubernetes Hardening Guidance by NSA and CISA Use Kubescape to test clusters or scan single YAML files and integrate it to your processes. Install curl -s https://raw.githubusercontent.com/armosec/kubescape/mast
ToolsLibAFL, the fuzzer library
Advanced Fuzzing Library – Slot your own fuzzers together and extend their features using Rust. LibAFL is written and maintained by Andrea Fioraldi andreafioraldi@gmail.com and Dominik Maier mail@dmnk.co. LibAFL is a collection of reusable pieces of fuzzers, written in Rust. It is fast, multi-platfo
Forensic ToolMobile Verification Toolkit For Pegasus Infection
Mobile Verification Toolkit (MVT) is a collection of utilities to simplify and automate the process of gathering forensic traces helpful to identify a potential compromise of Android and iOS devices. It has been developed and released by the Amnesty International Security Lab in July 2021 in the con
ExploitsHiveNightmare aka CVE-2021–36934
A zero-day exploit for HiveNightmare, which allows you to retrieve all registry hives in Windows 10 as a non-administrator user. For example, this includes hashes in SAM, which can be used to execute code as SYSTEM. How does this work? The permissions on key registry hives are set to allow all non-a
Burp SuiteDownload Burp Suite 2021.6
This release includes the following bug fixes. Playing back recorded login sequences is now more reliable when one of the elements in the series is hidden by other elements on the page. Recorded login sequences can now be tested correctly when you play them from the configuration library. Changes to
GitHubProfil3r – Profiles of a Person on Social Networks
Profil3r is an OSINT tool that allows you to find potential profiles of a person on social networks, as well as their email addresses. This program also alerts you to the presence of a data leak for the found emails. 💡 Prerequisite Python 3 Installation Install PyInquirer, jinja2 and bs4 : pip3 ins
GitHubWinbindex – The Windows Binaries Index
An index of Windows binaries, including download links for executables such as exe, dll and sys files. All linked binary files are hosted on the Microsoft public symbol server (msdl.microsoft.com), Winbindex merely indexes metadata that enables to generate those links. The website, along with the wh
Burp SuiteDownload Burp Suite 2021.5.1
What’s new in Burp Suite 2021.5.1 We have updated Burp Suite’s embedded browser to Chromium version 90.0.4430.212, which fixes several security issues that Google has classified as high. Bug fix: Payload processing rules that invoke extensions now display correctly. Windows Linux Jar Mac Burp Suite
GitHubRoutopsy – Tool to Hijack Network Routes
Routopsy is a toolkit built to attack often overlooked networking protocols. Routopsy currently supports attacks against Dynamic Routing Protocols (DRP) and First-Hop Redundancy Protocols (FHRP). Most of the attacks currently implemented make use of a weaponised ‘virtual router’ as opposed to implem
UncategorizedOWASP Mobile Security Testing Guide (MSTG).
The OWASP Mobile Security Testing Guide (MSTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the controls listed in the OWASP Mobile Application Verification Standard (MASVS). You can also read the MSTG on Gitbook or
ExploitsNexus Repository Manager CVE-2020-10199/10204
Nexus Repository Manager OSS/Pro: <=3.21.1 Nexus Repository Manager 3.21.1 http/s:/help.sonatype.com/repomanager3/download/ Nexus POCE Exploit https//github.com/wsfengfan/CVE-2020-10199-10204 Usage:python3 poc.py -i 127.0.0.1 -p 8081 -c cookie -csrf csrf-token 1), CVE-2020-10204 Manual verification
Linuxpspy tool – Monitor linux processes without root permissions
pspy – unprivileged Linux process snooping pspy is a command line tool designed to snoop on processes without need for root permissions. It allows you to see commands run by other users, cron jobs, etc. as they execute. Great for enumeration of Linux systems in CTFs. Also great to demonstrate your c
LinuxProgramming Linux Anti-Reversing Techniques
Programming Linux Anti-Reversing Techniques teaches the reader how to code and analyze well known anti-reversing techniques for Linux. The book shows how a reverse engineer analyzes a binary using tools like IDA, Radare2, GDB, readelf, and more. The code is presented to the reader ready to compile a
Bug FinderScanners Box : A Powerful Hackers Tool
Scanners Box also known as scanbox, is a powerful hacker toolkit, which collects more than 10 categories of open source scanners from Github, including subdomain, database, middleware and other modular design scanner etc. But for other Well-known scanning tools, such as nmap, w3af, brakeman, arachni
UncategorizedServer-side Request Forgery Detector
This is the application source code for the SSRF Detector website. The website has been EOL as of April 7th 2017, but the code has been updated to be run on a local machine. This documentation is a little touch-and-go as there is a lot of configuration for Nginx, SSL, etc… but for a local … Read mor
UncategorizedGorsair – Penetration Testing tool for Docker
Gorsair is a penetration testing tool for discovering and remotely accessing Docker APIs from vulnerable Docker containers. Once it has access to the docker daemon, you can use Gorsair to directly execute commands on remote containers. Exposing the docker API on the internet is a tremendous risk, as
ToolsHash Generator & Cracker Online Offline
#Install Note Clone the repository: git clone https://github.com/0xR0/hediye.git #Then go inside: cd hediye/ #use examples: python3 hediye.py -k Key / For –> Generate Hash (md5, sha1, sha224, sha256, sha384, sha512) python3 hediye.py -v HASH -f Wordlist / For –> Brute Force Attack (md5, sha1, sha224
AndroidPHANTOM EVASION 2.0.1- An Antivirus Evasion Tool
Phantom-Evasion is an interactive antivirus evasion tool written in python capable to generate (almost) FUD executable even with the most common 32 bit msfvenom payload (lower detection ratio with 64 bit payloads). The aim of this tool is to make antivirus evasion an easy task for pentesters through
Bug FinderXSShell – A XSS Reverse Shell Framework
XSShell is a cross-site-scripting reverse shell… Okay, well maybe it’s not a true reverse shell, but it will allow you to interact in real time with an XSS victim’s browser. XSShell also comes with a number of premade XSS payloads to use: alert – send a js alert message cs – get cookies and any … Re
GitHubZstandard – Fast real-time compression algorithm
Zstandard, or zstd as short version, is a fast lossless compression algorithm, targeting real-time compression scenarios at zlib-level and better compression ratios. It’s backed by a very fast entropy stage, provided by Huff0 and FSE library. The project is provided as an open-source dual BSD and GP
NetworkCloudBunny : Capture Real IP of Server behind WAF
CloudBunny is a tool to capture the origin server that uses a WAF as a proxy or protection. This tool we used three search engines to search domain information: Shodan, Censys and Zoomeye. To use the tools you need the API Keys, you can pick up the following links: Shodan – https://account.shodan.io
ExploitsFakeImageExploiter – Use a Fake Image to Exploit Target
This module takes one existing image.jpg and one payload.ps1 (input by user) and builds a new payload (agent.jpg.exe) that if executed it will trigger the download of the 2 previous files stored into apache2 (image.jpg + payload.ps1) and execute them. This module also changes the agent.exe Icon to m
Forensic ToolDFIRTrack: (Digital Forensics and Incident Response Tracking application
DFIRTrack (Digital Forensics and Incident Response Tracking application) is an open source web application mainly based on Djangousing a PostgreSQL database backend. In contrast to other great incident response tools, which are mainly case-based and support the work of CERTs, SOCs etc. in their dail
AndroidDROID-HUNTER – Android Pentesting Tool
Android application vulnerability analysis and Android pentest tool A. Support> App info check> Baksmaling android app> Decompile android app> Extract class file> Extract java code> Pattern base Information Leakage 2. How to Install?A. Download(clone) & Unpack DROID-HUNTER git clone https://github.c
JavaHackBar (Burpsuite Plugin)
RequirementsBurpsuiteJavaInstall Plugin Download Jar https://github.com/d3vilbug/HackBar/releases and add in burpsuite Tested on Burpsuite 1.7.36 Windows 7/8.1/10 Kali linux (2013.3) DOWNLOAD
ToolsStep: A tool to Make Work easier for zero trust technologies
Step is a zero trust swiss army knife. It’s an easy-to-use and hard-to-misuse utility for building, operating, and automating systems that use zero trust technologies like authenticated encryption (X.509, TLS), single sign-on (OAuth OIDC, SAML), multi-factor authentication (OATH OTP, FIDO U2F), encr
Post Exploitationp0wnedShell : Post Exploitation Toolkit
p0wnedShell is an offensive PowerShell host application written in C# that does not rely on powershell.exe but runs powershell commands and functions within a powershell runspace environment (.NET). It has a lot of offensive PowerShell modules and binaries included to make the process of Post Exploi
Post ExploitationBashark – Post exploitation toolkit
Introduction Bashark aids pentesters and security researchers during the post-exploitation phase of security audits. Usage To launch Bashark on compromised host, simply source the bashark.sh script from terminal: $ source bashark.sh Then type help to see Bashark’s help menu Features Single Bash scri
GitHubRepo Security Scanner – Search secrets from GitHub
repo-security-scanner CLI tool that finds secrets accidentally committed to a git repo, eg passwords, private keys Run it against your entire repo’s history by piping the output from git log -p Installation Download the latest stable release of the CLI tool for your architecture Extract the tar and
Forensic ToolStegextract: Extract Hidden files and strings from Images.
Description Stegextract extracts any trailing data after the image’s closing bytes, and any hidden files (or other images) embedded within the image. Short byte combinations such as JPEG’s FFD8 FFE0 might sometimes create false positives. Manually reviewing the hexdump is sometimes inevitable in cas
PentesterRaccoon: Tool for Reconnaissance and Information Gathering
Features DNS details DNS visual mapping using DNS dumpster WHOIS information TLS Data – supported ciphers, TLS versions, certificate details and SANs Port Scan Services and scripts scan URL fuzzing and dir/file detection Subdomain enumeration – uses Google dorking, DNS dumpster queries, SAN discover
ReconnaissancePhoton: Fast web crawler for Recon
Photon is a lightning fast web crawler which extracts URLs, files, intel & endpoints from a target. Usage -u –url Run Photon against a single website. python photon.py -u http://example.com Specifying a URL with it’s schema i.e. http(s):// is optional but you must add www. if the website has it. Tip
ReconnaissanceWAScan – Web Application Scanner
WAScan ((W)eb (A)pplication (Scan)ner) is a Open Source web application security scanner. It is designed to find various vulnerabilities using “black-box” method, that means it won’t study the source code of web applications but will work like a fuzzer, scanning the pages of the deployed web applica
BugBountyTakeover – SubDomain TakeOver Vulnerability Scanner
Sub-domain takeover vulnerability occur when a sub-domain (subdomain.example.com) is pointing to a service (e.g: GitHub, AWS/S3,..) that has been removed or deleted. This allows an attacker to set up a page on the service that was being used and point their page to that sub-domain. For example, if s
BugBountySubFinder – Powerfull Sub-domain Enumeration Tool
SubFinder is a subdomain discovery tool that uses various techniques to discover massive amounts of subdomains for any target. It has been aimed as a successor to the sublist3r project. SubFinder uses Passive Sources, Search Engines, Pastebins, Internet Archives, etc to find subdomains and then it u
BugBountySubOver – Subdomain Takeover Tool
Subover is a Hostile Subdomain Takeover tool originally written in python but rewritten from scratch in Golang. Since it’s redesign, it has been aimed with speed and efficiency in mind. Till date, SubOver detects 30+ services which is much more than any other tool out there. The tool uses Golang con
NetworkSandMap: Network and System Reconnaissance using Nmap engine.
Sandmap is a tool supporting network and system reconnaissance using the massive Nmap engine. It provides a user-friendly interface, automates and speeds up scanning and allows you to easily use many advanced scanning techniques. Key Features simple CLI with the ability to run pure Nmap engine prede
AndroidDroid Application Fuzz Framework
Droid Application Fuzz Framework (DAFF) helps you to fuzz Android Browsers and PDF Readers for memory corruption bugs in real android devices. You can use the inbuilt fuzzers or import fuzz files from your own custom fuzzers. DAFF consist of inbuilt fuzzers and crash monitor. It currently supports f
LinuxKRACK Detector: Know KRACK Attack on Your Network
KRACK Detector is a Python script to detect possible KRACK attacks against client devices on your network. The script is meant to be run on the Access Point rather than the client devices. It listens on the Wi-Fi interface and waits for duplicate message 3 of the 4-way handshake. It then disconnects
ToolsOfficial Black Hat Arsenal Tools Github Repository
This github account maps to the Black Hat Arsenal tools since its inception in 2011. For readibility, the tools are classified by category and not by session. This account is maintained by ToolsWatch.orgthe official organizer of the Black Hat Arsenal event Disclaimer: Tools not demonstrated during a
AppleSteel.Password- Easily get Apple users ID’s
Do you want the user’s Apple ID password, to get access to their Apple account, or to try the same email/password combination on different web services? Just ask your users politely, they’ll probably just hand over their credentials, as they’re trained to do so 👌 iOS asks the user for their iTunes
AndroidHijacker v1.3- WiFi Hacking Tool for Android
Hijacker is a Graphical User Interface for the penetration testing tools Aircrack-ng, Airodump-ng, MDK3 and Reaver. It offers a simple and easy UI to use these tools without typing commands in a console and copy&pasting MAC addresses. This application requires an ARM android device with a wireless a
AndroidRadare2- Debug Windows apps in Linux and Mac
r2 is a rewrite from scratch of radare in order to provide a set of libraries and tools to work with binary files. Radare project started as a forensics tool, a scriptable commandline hexadecimal editor able to open disk files, but later support for analyzing binaries, disassembling code, debugging
PentesterXSStrike: Fuzz, Crawl and Bruteforce Parameters for XSS
XSStrike is a python script designed to detect and exploit XSS vulnerabilites. Visit XSStrike’s project site for more info. A list of features XSStrike has to offer: Fuzzes a parameter and builds a suitable payload Bruteforces paramteres with payloads Has an inbuilt crawler like functionality Can re
Hash CrackerHash Buster – scraps online hash crackers to find cleartext of a hash
Hash Buster – scraps online hash crackers to find cleartext of a hash Hash Buster is a python script which uses several online hash crackers to find cleartext of a hash in less than 5 seconds. Features of Hash Buster: Detects hash MD5 Support SHA1 Support SHA2 Support Adding more APIs for SHA1 and S
PentesterInforFinder – tool to collect information of any domains pointing at some server
InforFinder – tool to collect information of any domains pointing at some server. Inforfinder is a tool made to collect information of any domain pointing at a server (ip,domain,range,file). Requires python libs: pyRequests and pyDNS -First, you need to install complementary libraries: user@machine$
AndroidHijacker-Wireless Auditing Tool for Android
Hijacker is a Graphical User Interface for the wireless auditing tools airodump-ng, aireplay-ng and mdk3. It offers a simple and easy UI to use these tools without typing commands in a console and copy&pasting MAC addresses. This application requires an android device with a wireless adapter that su
NetworkZoomEye- A Cyber Space Search Engine
ZoomEye is another cool web search engine, where users can search for the connected devices, ports and other things which helps to understand the network infrastructure for Pentest. Below image shows the shortcuts or keys to help for better search Check it Here
FirewallMorpheus – automated ettercap TCP/IP Hijacking tool
Version release : v1.7-Alpha Author : pedro ubuntu [ r00t-3xp10it ] Distros Supported : Linux Ubuntu, Kali, Mint, Parrot OS Suspicious-Shell-Activity (SSA) RedTeam develop @2016 LEGAL DISCLAMER The author does not hold any responsibility for the bad use of this tool, remember that attacking targets
Bug FinderLynis 2.2.0 – Security Auditing Tool for Unix/Linux Systems
Lynis is an open source security auditing tool. Commonly used by system administrators, security professionals and auditors, to evaluate the security defenses of their Linux/Unix based systems. It runs on the host itself, so it can perform very extensive security scans. Supported operating systems T
UncategorizedMobile-Security-Framework (MobSF) for Android and iOS
Mobile Security Framework (MobSF) is an intelligent, all-in-one open source mobile application (Android/iOS) automated pen-testing framework capable of performing static and dynamic analysis. It can be used for effective and fast security analysis of Android and iOS Applications and supports both bi
JoomlaProject Arsenal X – As HackTheGame But Real
Project Arsenal X New version of my Arsenal X written in Delphi with the following options: [+] Gmail Inbox [+] Whois Client [+] Table [+] Downloader [+] Get IP [+] Locate IP [+] K0bra SQLI Scanner [+] Crack multiple hashes [+] Search admin panel [+] Port Scanner [+] Multi Cracker with support for F
AndroidKali NetHunter 3.0 – Android Mobile Penetration Testing Platform
What’s New in Kali NetHunter 3.0 NetHunter Android Application Rewrite The NetHunter Android application has been totally redone and has become much more “application centric”. Many new features and attacks have been added, not to mention a whole bunch of community-driven bug fixes. The NetHunter ap
LinuxPhpsploit – Stealth Post-Exploitation Framework
PhpSploit is a remote control framework, aiming to provide a stealth interactive shell-like connection over HTTP between client and web server. It is a post-exploitation tool capable to maintain access to a compromised web server for privilege escalationpurposes. Overview The obfuscated communicatio
JoomlaJoomlavs – A Black Box, Joomla Vulnerability Scanner
JoomlaVS is a Ruby application that can help automate assessing how vulnerable a Joomla installation is to exploitation. It supports basic finger printing and can scan for vulnerabilities in components, modules and templates as well as vulnerabilities that exist within Joomla itself. How to install
LinuxBlade – A Webshell Connection Tool With Customized WAF Bypass Payloads
Blade is a webshell connection tool based on console, currently under development and aims to be a choice of replacement of Chooper (中国菜刀). Chooper is a very cool webshell client with widly typies of server side scripts supported, but Chooper can only work on Windows opreation system, so this is the
LinuxNipe – Script To Redirect All Traffic From The Machine To The Tor Network
Script to redirect all the traffic from the machine to the Tor network. [+] AUTOR: Vinicius Gouvea [+] EMAIL: vini@inploit.com [+] BLOG: https://medium.com/viniciusgouvea [+] GITHUB: https://github.com/HeitorG [+] FACEBOOK: https://fb.com/viniciushgouvea Installing: git clone https://github.com/Heit
LinuxSublist3R – Fast Subdomains Enumeration Tool For Penetration Testers
Sublist3r is python tool that is designed to enumerate subdomains of websites using search engines. It helps penetration testers and bug hunters collect and gather subdomains for the domain they are targeting. Sublist3r currently supports the following search engines: Google, Yahoo, Bing, Baidu, and
Bug FinderMosca – Static Analysis Tool To Find Bugs
Just another Simple static analysis tool to find bugs like a grep unix command, at mosca have a modules, that was call egg, each egg is a simple config to find bug at especific language like PHP,Ruby,ASP etc… Example of egg config at directory “egg”, If Mosca read a line with vunerability of egg in
SQLinjectionjSQL Injection v0.73 – Java Tool For Automatic SQL Database Injection
jSQL Injection is a lightweight application used to find database information from a distant server. jSQL is free, open source and cross-platform (Windows, Linux, Mac OS X, Solaris). jSQL is part of Kali Linux, the official new BackTrack penetration distribution. jSQL is also included in Black Hat S