
camjacking
CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

A DNS spoofer tool written in Python3.

This function combines all the above functions and takes necessary information from the user to change the IP and MAC address, start the responder…

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

Spoof emails from any of the +2 Million domains using MailChannels (DEFCON 31 Talk)

Python library and client for token manipulations and impersonations for privilege escalation on Windows

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Impersonate Logged In Accounts & Execute Commands

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

Scripts to clone CA certificates for use in HTTPS client attacks.

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

This script helps to pass through the captive portals in public Wi-Fi networks. It hijacks IP and MAC from somebody who is already connected and…

Emulates a Cisco ASA Anyconnect VPN service for credential harvesting and VBS payload delivery in red team phishing operations.

C# Reflective loader for unmanaged binaries.

A C# implementation of dumping credentials from Windows Credential Manager

Phishing with a fake reCAPTCHA

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…