
JS-Tap
JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

Automating Host Exploitation with AI

XFLTReaT tunnelling framework

Freedom Fighting Mode: open source hacking harness

High speed/Low cost CommonCrawl RegExp in Node.js

DNS tunneling tool using PowerShell and Nslookup to exfiltrate data and deliver payloads via DNS TXT/MX records, bypassing Constrained Language Mode…

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13

C# tool for red team operations that extracts contacts, mailbox metadata, and searches emails via Outlook COM object, with built-in Programmatic…

DLL Password Filter Implant with Exfiltration Capabilities

A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.

Real Time Threat Monitoring Tool

Azure Post Exploitation Framework

The CIA Hive source code as released by Wikileaks

The Outlook HTML Leak Test Project

Modified dropbear server which acts as a client and allows authless login

Exfiltrate sensitive user data from apps on Android 12 and 13 using CVE-2024-0044 vulnerability remotely

CVE-2020-9992 - A design flaw in MobileDevice.framework/Xcode and iOS/iPadOS/tvOS Development Tools allows an attacker in the same network to gain…