
OffensiveNim
My experiments in weaponizing Nim (https://nim-lang.org/)

My experiments in weaponizing Nim (https://nim-lang.org/)

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Dump cookies and credentials directly from Chrome/Edge process memory

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Bypasses PPL protection to dump LSASS process memory, obfuscates dump files with XOR, and exfiltrates them remotely via RAW or SMB without writing to…

LeakScraper is an efficient set of tools to process and visualize huge text files containing credentials. Theses tools are designed to help…

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Solitude is a privacy analysis tool that enables anyone to conduct their own privacy investigations. Whether a curious novice or a more advanced…

A standalone DLL that exports databases in cleartext once injected in the KeePass process.

High speed/Low cost CommonCrawl RegExp in Node.js

Adobe Reader DC Information Leak Exploit

Scan LLM outputs and AI-generated content for data exfiltration signals (EchoLeak, CVE-2025-32711) before they reach users or downstream systems

BlockGuard is a Windows Data Loss Prevention (DLP) agent that intercepts and controls file access at the process level. It ensures that only…


