
SpotifyC2
Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…

Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…

Just a repo of random Python scripts to get pentesters started with the Python language on engagements.

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Python-Based Pentesting CLI Tool

Enumerate user accounts and registered authentication methods via the Microsoft Self-Service Password Reset (SSPR) portal

Script lets you gather malicious software and c&c servers from open source platforms like Malshare, Malcode, Google, Cymon - vxvault, cybercrime…

Mass reconnaissance, version fingerprinting, CVE tester and live exploitation framework for Ollama open instances.

Autonomous security operations agent for threat intelligence, vulnerability research, IOC analysis, and red teaming. Supports dual-mode operations…

Uses Shodan API to pull down C2 servers to run known exploits on them.

Resources to learn more about Chinese-language cybercrime actors.

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

A proof of concept demonstrating how to use the Hinge dating app as a C2.

Red Team utilities for setting up CWP CentOS 7 payload & reverse shell (Red Team 9 - CW2023)

CVE-2024-3273 — Authorized Penetration Test Report D-Link DNS-320L NAS | Client: Otonata

Check simultaneously if a phone number is registered on popular apps & websites, without any prerequisite 📞

A modular OSINT & SOCMINT framework for social media intelligence, investigation, and public data analysis.

Live Feed of C2 servers, tools, and botnets