
iron-proxy
An egress firewall for untrusted workloads.
Tools for extracting sensitive data from compromised systems without detection.

An egress firewall for untrusted workloads.

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

Generates fully valid fake identities in Spanish format, including names, emails, bank details, and extended info, with optional zip compression and…

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

PowerShell script that invokes legitimate credential prompts and exfiltrates captured passwords over DNS using CredentialPicker and Resolve-DnsName.

Cross-platform framework for enumerating O365 accounts, password spraying, exfiltrating emails/Teams/OneDrive data, and backdooring EntraID accounts…

GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint…

Pupy is an opensource, multi-platform (Windows, Linux, OSX, Android), multi function RAT (Remote Administration Tool) mainly written in python. It…

Python-based keylogger with Telegram bot integration for capturing keystrokes, clipboard content, and screenshots in authorized security testing…

Android remote administration tool

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

The tool exfiltrates data from Couchbase database by exploiting N1QL injection vulnerabilities.

Steganography Tool for JPG Images

A Proof-of-Concept using Cache Smuggling + Exif data to passively download a second stage payload

Free advanced and modern Windows botnet with a nice and secure PHP panel developed using VB.NET.

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

Unauthenticated Jenkins CLI exploit scanner for CVE-2024-23897 that detects vulnerable versions and reads arbitrary files from the controller through…

CVE-2026-6765 · Test only FormAutofill handlers exposed in Firefox