
Penetration-Testing-Tools
A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security…

A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security…

Cloud, CDN, and marketing services leveraged by cybercriminals and APT groups

Curated dataset of confirmed phishing URLs from JPCERT/CC, including confirmation date, full URL, and spoofed brand for threat intelligence and…

A list of cyber-chef recipes and curated links

Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups

This repository contains indicators of compromise (IOCs) of our various investigations.


Automated man-in-the-middle attack tool.

Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs

OTP BOT Bypass SMS verifications from Paypal, Instagram, Snapchat, Google, 3D Secure, and many others...

Discovering CVE-2025-22381: Host Header Injection in the Aggie Open-Source Project

Resources to learn more about Chinese-language cybercrime actors.

HostHeaderInjection-Askey

The plugin does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone…


We are presented with a security alert indicating the detection of the Follina (CVE-2022-30190) vulnerability. A malicious Word document triggered…