
GraphSpy
Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Python ADB-based Android device management and security audit toolkit with an interactive menu for root detection, permission dumps, debuggable app…

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via Microsoft…

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

Syncord is a CLI-based file synchronization and storage tool that uses Discord as an encrypted file storage.

VeilTransfer is a data exfiltration utility designed to test and enhance the detection capabilities. This tool simulates real-world data exfiltration…

React2Shell Exploitation Tool (CVE-2025-55182)

Slack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace

Multi-protocol data exfiltration testing tool that simulates real-world egress scenarios over FTP, HTTP, HTTPS, DNS, ICMP, SMB, SMTP, and SFTP to…

Tool to search secrets in various filetypes.

A python based tool for exploiting and managing Android devices via ADB

A Remote Administration Tool for Android devices

Blue Pigeon is a Bluetooth-based data exfiltration and proxy tool to enable communication between a remote Command and Control (C2) server and a…

Web-Scale NoSQL Idempotent Cloud-Native Big-Data Serverless Plaintext Credential Search

Test a network's egress controls with various levels of success and failure.

Remote Administration Tool for Android devices