

Web-Scale NoSQL Idempotent Cloud-Native Big-Data Serverless Plaintext Credential Search

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Academic purposes only. Attack against Salesforce lightning with guest privilege.

A Slack bot phishing framework for Red Teaming exercises

Test a network's egress controls with various levels of success and failure.

Discord voice channel C2 framework for covert command and control operations. Transmits all data via RTP packets over voice channels, leaving no…

Machine Learning Network Share Password Hunting Toolkit

Cobalt Strike BOF that creates an LSASS minidump in memory and exfiltrates it over the C2 callback for offline credential parsing with Mimikatz or…

Exfiltrate data over screen interfaces

Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !

FARO - Document Sensitivity Detector

Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)

Static analysis CLI that scans codebases for LLM prompt-injection, data-exfiltration, jailbreak, and unsafe agent/tool vulnerabilities. Runs fully…

POC of CVE-2026-51031 for arbitrary local file read

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

Reproduction lab for CVE-2026-54316 (Claude Code WebFetch huggingface.co bare-hostname permission bypass / exfiltration)