Swurg : Parse OpenAPI Documents Into Burp Suite For Automating OpenAPI-based APIs Security Assessments

4 years ago

Swurg is a Burp Suite extension designed for OpenAPI testing. The OpenAPI Specification (OAS) defines a standard, programming language-agnostic interface…

STEWS : A Security Tool For Enumerating Web Sockets

4 years ago

STEWS is a tool suite for security testing of Web Sockets This research was first presented at OWASP Global AppSec US…

Toutatis : A Tool That Allows You To Extract Information From Instagram Accounts Such As E-Mails, Phone Numbers And More

4 years ago

Toutatis is a tool that allows you to extract information from instagrams accounts such as e-mails, phone numbers and moreFor…

Forbidden : Bypass 4Xx HTTP Response Status Codes

4 years ago

Forbidden is to Bypass 4xx HTTP response status codes. Based on PycURL. Script uses multithreading, and is based on brute forcing…

AirStrike : Automatically Grab And Crack WPA-2 Handshakes With Distributed Client-Server Architecture

4 years ago

AirStrike is a tool that automates cracking of WPA-2 Wi-Fi credentials using client-server architecture. Requirements Airstrike uses Hashcat Brain Architecture, aircrack-ng suite, entr utility…

IAM Vulnerable : Use Terraform To Create Your Own Vulnerable By Design AWS IAM Privilege Escalation Playground

4 years ago

IAM Vulnerable is to use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.. IAM Vulnerable uses the…

IDA2Obj : Static Binary Instrumentation

4 years ago

IDA2Obj is a tool to implement SBI (Static Binary Instrumentation). The working flow is simple: Dump object files (COFF) directly from one executable binary.Link the object files into…

DLLHijackingScanner : This Is A PoC For Bypassing UAC Using DLL Hijacking And Abusing The “Trusted Directories” Verification

4 years ago

DLLHijackingScanner is a PoC for bypassing UAC using DLL hijacking and abusing the "Trusted Directories" verification. Generate Header from CSV The python script CsvToHeader.py can be…

ClusterFuzzLite : Simple Continuous Fuzzing That Runs In CI

4 years ago

ClusterFuzzLite is a continuous fuzzing solution that runs as part of Continuous Integration (CI) workflows to find vulnerabilities faster than ever before. With just…

Crawpy : Yet Another Content Discovery Tool

4 years ago

Crawpy is Yet another content discovery tool written in python. What makes this tool different than others: It is written…