
MANSPIDER
Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!

Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!

PowerShell tool for transferring files in restricted environments (Citrix, RDP, VNC, Guacamole) via clipboard, Base64 chunks, keystrokes, or OCR…

Covert file-transfer tool using DNS-over-HTTPS: encodes payload chunks in TXT records, applies XOR obfuscation, and can execute shellcode for…

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Steganograpy in Python | Hide files or data in Image Files

GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint…


CVE-2025-66723: inMusic Brands Engine DJ >=3.0.0 through <4.3.4 exposes local and network files to external parties

将文件隐写进MP4/MKV文件中 (Embed files into MP4/MKV files.)

Extract the SAM and SYSTEM hives using the Volume Shadow Copy (VSS) API. With exfiltration and XOR obfuscation options. In C#, C++, Crystal, Python,…

This binary POC automates the exploitation of CVE-2024-36991 by sending crafted curl requests to a vulnerable Splunk instance. It retrieves sensitive…

Google Drive, OneDrive and Youtube as covert-channels - Control systems remotely by uploading files to Google Drive, OneDrive, Youtube or Telegram

A simple utility to convert EXE files to JPEG images and vice versa.

Language Sloth Sloth Bot 1.0 is vulnerable to Directory Traversal in the gif() and png() functions. The functions build file paths using unsanitized…

Bypasses PPL protection to dump LSASS process memory, obfuscates dump files with XOR, and exfiltrates them remotely via RAW or SMB without writing to…

Proof-of-concept exploit for CVE-2022-3656, a Chrome/Chromium vulnerability enabling theft of sensitive files like encrypted wallets and cloud…

Unauthenticated Jenkins CLI exploit scanner for CVE-2024-23897 that detects vulnerable versions and reads arbitrary files from the controller through…