[ 0.000000]
arsenal v2.0 — loading modules...
[ 0.124712]
init: scanning payload directories...
[ 0.283415]
init: 8 modules registered
[ 0.291003]
init: ready.
type 'help' for available commands
Th3 L4ughingM4n's
Arsenal
A collection of payloads and tools for authorized security testing.
← Main Site
Arsenal
$
./list_modules
⚡
xss
Cross-site scripting — cookie stealers, keyloggers, DOM manipulation
12 payloads
💉
sqli
SQL injection — time-based, error-based, blind, out-of-band
10 payloads
📄
xxe
XML External Entity — file disclosure, SSRF, OOB exfiltration
8 payloads
💻
cmdi
Command injection — Linux, Windows, blind, out-of-band
8 payloads
🔧
ssti
Server-side template injection — Jinja2, Twig, Freemarker, Velocity
10 payloads
📡
ssrf
Server-side request forgery — cloud metadata, internal networks
8 payloads
📁
lfi
File inclusion — local, remote, wrappers, log poisoning
10 payloads
🔓
auth
Authentication bypass — session attacks, JWT, OAuth misconfigs
8 payloads