
beef
The Browser Exploitation Framework Project

The Browser Exploitation Framework Project

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.

Venom is a library that meant to perform evasive communication using stolen browser socket

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Post Exploitation agent which uses a browser to do C2 operations.

Reverse engineering analysis of AcrStealer, a sophisticated info-stealer that uses custom protocols, browser credential theft, and payload…

Hooked browser communication over MQTT

Automated browser crash tool exploiting CVE-2020-27950 (iOS WebKit) via Metasploit and ngrok. Generates public malicious URL for controlled…

Proof-of-concept exploit for CVE-2026-54088, a pre-authentication OS command injection in File Browser <=2.63.5. Demonstrates shell injection via…

Manual, non-Metasploit authenticated Remote Code Execution (RCE) exploit via the browser URL bar for Webmin 1.580 (CVE-2012-2982)

A tool to transform Chromium browsers into a C2 Implant

Filesystem interaction via firebeam virtual machine execution

CVE-2021-21220 Exploitation infrastructure

Browser-based CVE-2021-21220 exploit delivering a reverse shell via shellcode and a C2 implant for remote command execution on Windows targets.