
poisontap
Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.

USB Army Knife – the ultimate close access tool for penetration testers and red teamers.

Automated email OSINT tool that verifies emails, checks data breaches and password leaks, finds related emails/domains, scans pastebin dumps, and…

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

Automated OSINT framework for reconnaissance, data harvesting, and threat intelligence gathering with modular crawlers, scanners, and extraction…

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Curated collection of red team and pentest tools grouped by phase: payloads, AMSI bypasses, pivoting, persistence, privesc, credential harvesting,…

OSINT tool to find breached emails, databases, pastes, and relevant information

Real-time geospatial OSINT platform aggregating flight, vessel, and satellite data with dark web search, social media dorking, and AI-powered…

AI-powered threat intelligence platform for automated CVE/ransomware monitoring, domain surveillance, data leak detection, and incident response with…

KeySweeper is a stealthy Arduino-based device, camouflaged as a functioning USB wall charger, that wirelessly and passively sniffs, decrypts, logs…

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

PCI Express DIY hacking toolkit for Xilinx SP605. This repository is also home of Hyper-V Backdoor and Boot Backdoor, check readme for links and info