Starred repositories
Scanning APK file for URIs, endpoints & secrets.
Automating situational awareness for cloud penetration tests.
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug b…
Perfect DLL Proxying using forwards with absolute paths.
NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js
hackinaggie / OSEP-Tools-v2
Forked from Octoberfest7/OSEP-ToolsA marriage between Octoberfest7/OSEP-Tools and chvancooten/OSEP-Code-Snippets with some improvements/additions
PAYGoat is a banking application built for educational purposes, focused on exploring and understanding common business logic flaws in financial platforms.
The all-in-one Desktop & Docker AI application with built-in RAG, AI agents, No-code agent builder, MCP compatibility, and more.
🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.
A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.
A collection of useful tools and scripts were developed and gathered throughout the Offensive Security's PEN-300 (OSEP) course.
Scanner for the SharePoint CVE-2025-53770 RCE zero day vulnerability.
SharePoint WebPart Injection Exploit Tool
Advanced LLM-powered brute-force tool combining AI intelligence with automated login attacks
MapperPlus facilitates the extraction of source code from a collection of targets that have publicly exposed .js.map files.
Proof of Concept for CVE-2025-32463 Local privilege escalation exploit targeting sudo -R on vulnerable Linux systems. For educational and authorized security testing only.
✨ Fully autonomous AI Agents system capable of performing complex penetration testing tasks
Source code about machine learning and security.
a Curated list of Grafana Security Vulnerabilities, CVE & exploit
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user
A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager
A tool to extract the IdP cert from vCenter backups and log in as Administrator
POC for Veeam Backup and Replication CVE-2023-27532
A tool to query for the existence of pre-windows 2000 computer objects.