– Bring-Your-Own-Script-Interpreter – Leveraging the abuse of trusted applications, one is able to deliver a compatible script interpreter for a …


– Bring-Your-Own-Script-Interpreter – Leveraging the abuse of trusted applications, one is able to deliver a compatible script interpreter for a …

JA4+ is a suite of network Fingerprinting methods that are easy to use and easy to share. These methods are both …

A command line Windows API tracing tool for Golang binaries. Note: This tool is a PoC and a work-in-progress prototype …

TL;DR: Galah (/ɡəˈlɑː/ – pronounced ‘guh-laa’) is an LLM (Large Language Model) powered web honeypot, currently compatible with the OpenAI …

Essential utilities for pentester, bug-bounty hunters and security researchers secbutler is a utility tool made for pentesters, bug-bounty hunters and …

navgix is a multi-threaded golang tool that will check for nginx alias traversal vulnerabilities Techniques Currently, navgix supports 2 techniques …

Finding assets from certificates! Scan the web! Tool presented @DEFCON 31 ** You must have CGO enabled, and may have …

Description Easy EASM is just that… the easiest to set-up tool to give your organization visibility into its external facing …
DorXNG is a modern solution for harvesting OSINT data using advanced search engine operators through multiple upstream search providers. On …
EndExt is a .go tool for extracting all the possible endpoints from the JS files When you crawll all the …