The Rot Hackers Arsenal.
A comprehensive index of our open-source tools, scripts, and programming languages. Each project is actively maintained, heavily tested, and free to use.
WSHawk
v3.0.3Advanced WebSocket vulnerability scanner and exploitation framework. Capable of discovering SQL injection, XSS, and SSRF vulnerabilities over stateful, duplex connections.
Basilisk
v0.1.0AI/LLM red teaming framework with genetic prompt evolution. 29 attack modules, OWASP LLM Top 10 coverage, and Smart Prompt Evolution (SPE-NL) engine that breeds bypasses.
Zara RE Framework
v1.0.1Cross-platform reverse engineering framework built in C++ with native Qt desktop app. Binary disassembly, SSA-based decompiler, ptrace debugger, Python scripting, C SDK, distributed runners, AI-assisted analysis, and plugin ecosystem. Ships on 5 platforms.
ProtoCrash
v1.4.0Coverage-guided network protocol fuzzer written in Python. Capable of fuzzing proprietary binary protocols to discover memory corruption and crash logic.
PoCSmith
AI/GGUFAI-driven Proof-of-Concept exploit generator running locally using quantized models (CodeLlama, Llama 3) to convert vulnerability writeups into weaponized code.
SQL Tamper Framework
v2.1.0AST-based SQL transformation engine for SQLMap. Designed specifically to bypass modern cloud WAFs like Cloudflare, AWS, and Azure using 2025 evasion patterns.
GraphQL Scanner
AsyncHigh-speed, asynchronous GraphQL security scanner covering introspection abuse, batch query DoS, and nested field injection. Includes Burp Suite integration.
Keikaku
Pre-AlphaA custom, interpreted programming language written from scratch in Python. Designed as a research environment for complex, asynchronous payload generation.
More in Development
We are constantly researching and prototyping new attack techniques. Follow our GitHub to stay updated on unreleased tools.