
BlackDir-Framework
Web Application Vulnerability Scanner

Web Application Vulnerability Scanner

Fast subdomain takeover scanner with 50+ signatures, supporting cloud provider integrations (AWS, Azure, Cloudflare) and CI/CD pipeline mode for…

🔐 A CLI tool to extract server certificates

An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for…

Exploit and detect tools for CVE-2020-0688

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

Fast subdomain enumeration tool written in python.

POC shows how to leak postgresql stuff cause hugefile sub-system. Based on https://x.com/spendergrsec/status/1993794163880718700?s=20

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading

A python tool to check subdomain takeover vulnerability

🐶 A curated list of Web Security materials and resources.

Auto malicious git repository creation to exploit CVE-2018-11235 a Remote Code Execution using Git Sub module.

SubSeven Legacy Official Source Code Repository


Apply a divide and conquer approach to bypass EDRs

This extension enhances Burp Suite by adding several UI and functional features, making it more user-friendly.


Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain