
Tools for extracting sensitive data from compromised systems without detection.


Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

VeilTransfer is a data exfiltration utility designed to test and enhance the detection capabilities. This tool simulates real-world data exfiltration…

Dump cookies and credentials directly from Chrome/Edge process memory

Smart keylogging capability to steal SSH Credentials including password & Private Key

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Python3 utility for creating zip files that smuggle additional data for later extraction

Various tips & tricks

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.




CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept

All the materials for Gareth Heyes' Black Hat talk: CSS: the bomb inside your inbox.

Notepad++ CVE-2026-52886 — session.xml backupFilePath starts_with() path traversal (GHSA-rqfm-pw34-r7j6)

方便实用的CVE-2026-39363利用工具

Covert data exfiltration via DNS