
mTLS-Encrypted Back-Connect SOCKS5 Proxy enabling secure tunneled connections through NAT systems.

SoaPy is a Proof of Concept tool for conducting offensive interaction with Active Directory Web Services from Linux hosts.

A Burp Suite plugin designed for automated fuzz testing of file upload vulnerabilities with over 500 payloads.

A powerful authorization enforcement detection extension for Burp Suite that reduces false positives with AI assistance.

ZigStrike is a powerful Payload Delivery Pipeline developed in Zig, offering various injection techniques and anti-sandbox features.

EWSTool is a post-exploitation tool for Exchange mail servers, enabling email list retrieval, email search, and email download.

Promptfoo is a local tool for testing LLM applications with security evaluations and performance comparisons.

Useful Techniques, Tactics, and Procedures for red teamers and defenders, alike!

BrowserBruter is a powerful web form fuzzing automation tool designed for web security professionals and penetration testers.

A PowerShell tool for dominating Active Directory, inspired by CrackMapExec and NetExec.

TREVORspray is a modular password sprayer with threading, clever proxying, loot modules, and more!

A tool for brute forcing weak passwords on FTP, SSH, MySQL, MSSQL, etc.