
Paste2Web
A python3 script that uses cl1p website to send and receive secret messages

A python3 script that uses cl1p website to send and receive secret messages

JA4+ is a suite of network fingerprinting standards

Fast, comprehensive DNS performance testing with DNSSEC validation, DoH/DoT support, and enterprise features

Web Application Vulnerability Scanner

A exploit tool for Grafana Unauthorized arbitrary file reading vulnerability (CVE-2021-43798), it can burst plugins / extract secret_key / decrypt…

Collection of Brute Ratel C4 BOFs for Windows post-exploitation: process memory access, NetNTLMv2 hash retrieval, contact harvesting, and…

Laravel Crypto Killer Mass Scanner (CVE-2024-55555)

Exploit for CVE-2020-2733 in JD Edwards EnterpriseOne Tools, demonstrating unauthenticated admin password decryption and authentication bypass to…

A Python agent targeting Linux for Mythic C2

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

Penetration Testing and Hacking CTF's Swiss Army Knife with: Reverse Shell Handling - Encoding/Decoding - Encryption/Decryption - Cracking Hashes /…

A reverse shell with terminal support, data tunneling, and advanced pivoting capabilities.

Active Directory NTDS database parser that dumps records to JSON, supports object filtering, and decrypts encrypted columns using SYSTEM hive or…

Decrypt GlobalProtect configuration and cookie files.

Catch what's lurking in your Kafka clusters.

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from…

A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.