mitsec

Arsenal

Offensive tooling

Every tool is pure Python stdlib — no pip, no vendoring. Colored terminal output, JSON/JSONL export, stdin pipeline support and severity-based exit codes, so they chain straight into subfinder | httpx | tool --stdin.

NextSniper

exploit

Next.js exploitation scanner — CVE-2025-29927 & CVE-2025-55182 middleware bypass + RSC traversal modules. Confirmed RCE on production AWS EC2.

Python · stdlib onlygithub ↗

FridHunter

mobile

Rootless Android pentest suite via Frida Gadget injection on Termux. 8-layer SSL pinning bypass, secret scanner, schema-aware deeplink fuzzer, autopilot.

Python · stdlib onlygithub ↗

NextScope

recon

Next.js / Vercel bundle intelligence — chunk harvesting, source-map recovery, endpoint & secret extraction with an HTML report per target.

Python · stdlib onlygithub ↗

HeaderHunter

scanner

POST endpoint discovery + HTML form parsing with body-parameter injection across SQLi / XSS / SSTI / RCE / LFI / CRLF / Open Redirect.

Python · stdlib onlygithub ↗

FortiSniper

exploit

CVE-2026-21643 scanner for FortiClientEMS — PostgreSQL injection via Site header, CAST-trick error extraction, time-based blind fallback.

Python · stdlib onlygithub ↗

ShodanMap

recon

Shodan REST asset mapper — multi-query harvest, DNS domain API, IP↔port↔domain↔cert correlation and httpx target generation.

Python · stdlib onlygithub ↗

JSHunter

recon

JavaScript source intelligence — endpoint, secret and sink discovery across bundled front-end assets.

Python · stdlib onlygithub ↗

WebProbe v2

scanner

Fast HTTP probe with fingerprinting, tech detection and pipeline-friendly JSONL output.

Python · stdlib onlygithub ↗

SandboxSniper

exploit

FortiSandbox unauthenticated OS command injection scanner (CVE-2026-39808) with canary-based false-positive prevention.

Python · stdlib onlygithub ↗
↑↓ navigate↵ openesc close