
cyberchef-recipes
A list of cyber-chef recipes and curated links

A list of cyber-chef recipes and curated links

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

A curated list of useful resources that cover Offensive AI.

XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

The plugin does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone…

Proof-of-concept exploit for CVE-2018-13257 demonstrating CAS host header spoofing in Blackboard Learn to hijack user sessions via a malicious…

Autoencoder-based anomaly detection for identifying phishing domains using CERT Polska warning list data, with Jupyter notebooks for research and…

Discovering CVE-2025-22381: Host Header Injection in the Aggie Open-Source Project

Proof-of-concept exploit for CVE-2026-33149, a Host header injection in Tandoor Recipes that enables invite link poisoning and cache poisoning.…

Proof-of-concept for open redirection via Host header manipulation in Sielox AnyWare 2.1.2 (CVE-2024-34328), with exploit steps, impact, and…

a low(zero) cost threat intelligence&response tool against phishing domains

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Accurately Locate Smartphones using Social Engineering

Send phishing messages and attachments to Microsoft Teams users

Bulk domain spoofability checker using authoritative SPF and DMARC record analysis with custom, real-world tested spoof logic and optional DKIM…

Automates phishing and post-phishing activities with an almost-transparent reverse proxy that dynamically mirrors target web apps and interacts with…