
malicious-pdf
Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Open-Source Remote Administration Tool For Windows C# (RAT)

A collaborative, multi-platform, red teaming framework

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

DNS Exfiltration tool for stealthily sending files over DNS requests.

Get Keyboard,Mouse,ScreenShot,Microphone Inputs from Target Computer and Send to your Mail.

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

My experiments in weaponizing Nim (https://nim-lang.org/)


Encrypted command-and-control tunnel over DNS protocol. Creates stealthy C&C channels for penetration testing, with file transfer, shell access, and…

Cross-platform CLI for network performance testing over TCP, UDP, HTTP, HTTPS, and ICMP: bandwidth, connections/s, packets/s, latency, loss, jitter,…

USB Army Knife – the ultimate close access tool for penetration testers and red teamers.

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Windows Remote-Access-Trojan

(extensible) Data Exfiltration Toolkit (DET)

CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept