Open-source security tools and exploit development
Discovers and hijacks live SSH agent sockets on a compromised Linux system. Finds active SSH_AUTH_SOCK entries across running processes, validates which sockets have keys loaded, and surfaces them for immediate use—no disk writes, no cracking, no private key files required.
View RepositoryEnumerates wireless network information from a Linux system: interface details, nearby APs using weak encryption (WEP/TKIP) or WPS, and saved PSKs harvested from NetworkManager profiles and wpa_supplicant.conf.
View RepositoryScans shell and application history files across all users on a Linux system for credentials, tokens, secrets, and authenticated curl/wget-style network requests left in plaintext—credential keywords, Bearer headers, API keys, and inline basic auth patterns.
View RepositoryExecute a payload entirely in memory without ever writing it to disk—Linux memfd-style fileless execution for research and authorized assessments.
View RepositoryChecks whether the host’s runc version is affected by CVE-2024-21626 (Leaky Vessels): locates runc in common paths or on PATH, parses the runc version string, and flags releases before 1.1.12 as vulnerable—useful for patching and image rebuild decisions on container nodes.
View RepositoryLinux security auditing tool that walks the proc filesystem, prints each running process (PID, comm, user, cmdline), and flags writable execution targets when a process runs as root but a resolved path is not owned by root and is group- or world-writable—a common privilege-escalation signal.
View RepositoryComprehensive SPIP CMS security scanner. Features WAF detection, version fingerprinting, CVE auto-exploitation (CVE-2023-27372, CVE-2024-7954, CVE-2024-8517), user enumeration, password spraying, SSTI/XSS/path traversal testing, and composer.lock analysis.
View RepositoryFast subdomain enumeration via crt.sh Certificate Transparency logs with parallel DNS resolution. Features color-coded output, JSON export, stdin support for batch processing, and auto-retry with exponential backoff. Zero external dependencies.
View RepositoryAdvanced SSH security testing and auditing tool. Performs comprehensive SSH server analysis, vulnerability detection, and configuration assessment.
View RepositoryLinux kernel exploitation toolkit. Collection of kernel exploit techniques, privilege escalation methods, and kernel security research tools.
View RepositorySudo vulnerability scanner and exploitation framework. Detects misconfigured sudo permissions and known sudo vulnerabilities for privilege escalation.
View RepositoryURL vulnerability scanner and exploitation toolkit. Discovers and exploits common web application vulnerabilities through URL parameter manipulation.
View RepositoryAutomated vulnerability scanner for CVE-2025-68461. Detects vulnerable systems and provides detailed exploitation guidance for security assessments.
View RepositoryComprehensive reconnaissance framework for bug bounty hunters. Features subdomain enumeration, vulnerability scanning (XXE, SSRF, SSTI, NoSQLi, CRLF), SMB/FTP testing, and automated security assessments.
View RepositoryAutomated exploitation framework for discovering and exploiting known vulnerabilities. Streamlines the process of identifying vulnerable targets and launching appropriate exploits.
View RepositoryGraphQL security testing toolkit. Performs introspection queries, schema analysis, and vulnerability detection for GraphQL APIs including authentication bypass and injection attacks.
View RepositoryFast DNS resolution and enumeration tool. Performs bulk DNS lookups, subdomain discovery, and DNS record analysis for reconnaissance and security assessments.
View RepositoryAdvanced web technology detection and vulnerability assessment tool. Combines Wappalyzer, custom fingerprinting, and Nuclei with multi-source CVE enrichment from NVD, OSV, ExploitDB, Vulners, and Metasploit.
View RepositoryWeb application vulnerability scanner and exploitation framework. Automates the discovery and exploitation of common web vulnerabilities for penetration testing engagements.
View RepositorySpring Boot Actuator security scanner and exploitation tool. Discovers exposed actuator endpoints and exploits misconfigurations for information disclosure and remote code execution.
View Repository