Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods. This tool is designed to automate the process of exploiting XXE vulnerabilities, making it easier for security researchers and penetration testers to identify and exploit these types of vulnerabilities. The tool supports multiple methods of exploitation, including direct and out-of-band methods, and provides a user-friendly interface for configuring and running attacks.
FEATURES
SIMILAR TOOLS
A Python script that finds endpoints in JavaScript files to identify potential security vulnerabilities.
Joe Sandbox Community provides automated cloud-based malware analysis across multiple OS platforms.
Fernflower is an analytical decompiler for Java with command-line options and support for external classes.
A binary analysis and management framework for organizing and analyzing malware and exploit samples, and creating plugins.
A collection of Yara rules for identifying malicious PEs with unique or suspicious PDB paths.
ILSpy is the open-source .NET assembly browser and decompiler with various decompiler frontends and features.
A cutting-edge AI-based IT security platform that identifies malware and cyber-attacks within seconds
RetDec is a versatile machine-code decompiler with support for various file formats and architectures.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.