
nextdns
Command-line DNS-over-HTTPS client and proxy for encrypted, tamper-resistant DNS resolution; works with any DoH provider and supports split-horizon…

Command-line DNS-over-HTTPS client and proxy for encrypted, tamper-resistant DNS resolution; works with any DoH provider and supports split-horizon…

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

Multi-hop proxy tool for pentesters enabling traffic routing through multiple nodes, SOCKS5/SSH tunneling, port forwarding, remote shell, and…

Multi-module offensive security toolkit for SOCKS5 proxy chaining, port scanning, DNS enumeration, hash cracking, reverse shell generation,…

Flexible DNS proxy with encrypted protocol support (DNSCrypt v2, DoH, ODoH, Anonymized DNS), caching, filtering, load balancing, and cloaking for…

Trusted localhost HTTPS — local CA, /etc/hosts, mDNS LAN sharing, reverse proxy. Maps https://name.local → localhost:port

Automated script for setting up CobaltStrike redirectors (nginx reverse proxy, letsencrypt)

Transparent man-in-the-middle proxy that terminates SSL/TLS connections, forges certificates on-the-fly, and logs decrypted traffic for network…

Open-source VPN protocol that tunnels TCP, UDP, and ICMP traffic over HTTPS, bypassing DPI and throttling. Features split tunneling, SOCKS5 proxy,…

A censorship circumvention tool to evade detection by authoritarian state adversaries

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

A starttls-capable transparent man-in-the-middle proxy

A high-speed covert tunnel that disguises TCP traffic as SMTP email communication to bypass Deep Packet Inspection (DPI) firewalls.

A C2 post-exploitation framework

SAML2 Burp Extension

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.