The Rot Hackers Arsenal.
A comprehensive index of our open-source tools, scripts, and programming languages. Each project is actively maintained, heavily tested, and free to use.
WSHawk
v3.0.3Advanced WebSocket vulnerability scanner and exploitation framework. Capable of discovering SQL injection, XSS, and SSRF vulnerabilities over stateful, duplex connections.
ProtoCrash
v1.4.0Coverage-guided network protocol fuzzer written in Python. Capable of fuzzing proprietary binary protocols to discover memory corruption and crash logic.
PoCSmith
AI/GGUFAI-driven Proof-of-Concept exploit generator running locally using quantized models (CodeLlama, Llama 3) to convert vulnerability writeups into weaponized code.
SQL Tamper Framework
v2.1.0AST-based SQL transformation engine for SQLMap. Designed specifically to bypass modern cloud WAFs like Cloudflare, AWS, and Azure using 2025 evasion patterns.
GraphQL Scanner
AsyncHigh-speed, asynchronous GraphQL security scanner covering introspection abuse, batch query DoS, and nested field injection. Includes Burp Suite integration.
Keikaku
Pre-AlphaA custom, interpreted programming language written from scratch in Python. Designed as a research environment for complex, asynchronous payload generation.
More in Development
We are constantly researching and prototyping new attack techniques. Follow our GitHub to stay updated on unreleased tools.
View Organization GitHub