Find authentication (authn) and authorization (authz) security bugs in web application routes: Web application HTTP route authn and authz bugs …


Find authentication (authn) and authorization (authz) security bugs in web application routes: Web application HTTP route authn and authz bugs …

AntiSquat leverages AI techniques such as natural language processing (NLP), large language models (ChatGPT) and more to empower detection of …

Airgorah is a WiFi auditing software that can discover the clients connected to an access point, perform deauthentication attacks against …

Rayder is a command-line tool designed to simplify the orchestration and execution of workflows. It allows you to define a …

Introducing Uscrapper 2.0, A powerfull OSINT webscrapper that allows users to extract various personal information from a website. It leverages …

gssapi-abuse was released as part of my DEF CON 31 talk. A full write up on the abuse vector can …

This is a tool I whipped up together quickly to DCSync utilizing ESC1. It is quite slow but otherwise an …

FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more …

Python partial implementation of SharpGPOAbuse by@pkb1s This tool can be used when a controlled account can modify an existing GPO …

Finding assets from certificates! Scan the web! Tool presented @DEFCON 31 ** You must have CGO enabled, and may have …