
JS-Tap
JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

Weaponizes Selenium to automate credential theft, cookie dumping, email exfiltration, and file extraction from Chromium browsers for red team…

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

Paperweight scans your inbox to map your digital footprint, then helps you take back control and delete your data. Local-first and open source.

Transfer files to and from a Windows host via ICMP in restricted network environments.

Solitude is a privacy analysis tool that enables anyone to conduct their own privacy investigations. Whether a curious novice or a more advanced…

A Powerful Penetration Tool For Automating Penetration Tasks Such As Local Privilege Escalation, Enumeration, Exfiltration and More... Use Or Build…

LeakScraper is an efficient set of tools to process and visualize huge text files containing credentials. Theses tools are designed to help…

Keylogging server and client that uses DNS tunneling/exfiltration to transmit keystrokes through firewalls.

A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.

Etherify - bringing the ether back to ethernet

This tool is a command line utility that allows you to convert any binary file into a QRcode movie. The data can then be reassembled visually…

File Injector is a script that allows you to store any file in an image using steganography

DNS tunneling tool using PowerShell and Nslookup to exfiltrate data and deliver payloads via DNS TXT/MX records, bypassing Constrained Language Mode…

Injects JavaScript keylogger into WebView2 pages to capture keystrokes and exfiltrate cookies from Microsoft authentication sessions via HTTP GET…

A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.

Recursively searches files for sensitive information using customizable regex patterns, designed for penetration testers to rapidly discover secrets…