
maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites

🕵️♂️ Collect a dossier on a person by username from 3000+ sites

real time face swap and one-click video deepfake with only a single image

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

Phishing simulation and awareness framework for node-based campaigns, credential capture, SMTP delivery, CAPTCHA, and optional browser credential…

Advanced per-app device / CPU / GPU spoofer for rooted Android — device profiles, per-app CPU models, prop & Android-ID spoofing, all driven by a…

Transparent reverse proxy for penetration testing that bypasses 2FA, harvests credentials, and proxies multi-domain TLS traffic without client…

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…

Windows tool that disguises executable files by spoofing their icons and extensions using Unicode RLO characters, making .exe, .scr, and .com files…

Automates phishing and post-phishing activities with an almost-transparent reverse proxy that dynamically mirrors target web apps and interacts with…

Hunt down social media accounts by username across social networks

Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects…

In-target C# post-exploitation tool for Microsoft SQL Server (MS SQL / MSSQL) traversing linked-server chains of any depth with cascading login…

CI/CD pipeline exploitation tool for extracting secrets across Azure DevOps, GitHub, and GitLab by deploying malicious pipelines with automated trace…

USB Army Knife – the ultimate close access tool for penetration testers and red teamers.

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

HTTP/HTTPS interception proxy for testing Windows authentication mechanisms, supporting NTLM, Kerberos, pass-the-hash, pass-the-ticket and relay…