
tirith
Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens

Cyber threat intelligence platform for SSL certificate discovery, domain/URL scanning, data leak monitoring, tracking link generation, and threat…

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

Fully undetected grabber (grabs wallets, passwords, cookies, modifies discord client etc.)

A toolkit to attack Office365

CVE-2024-42009 Proof of Concept

A new approach to Browser In The Browser (BITB) without the use of iframes, allowing the bypass of traditional framebusters implemented by login…

Generate Gmail Emailing Keyloggers to Windows.

Node.js command-and-control server with FUD payload generation, encrypted communication, session management, and modules for data exfiltration and…

⭐️The famous XWorm RAT, version 2.1. Educational purposes only

Clone and import Chromium cookies and passwords across browsers with offline DPAPI state key decryption, supporting AES-256 GCM encrypted databases…

A simple python reverse shell written just for fun.

Public disclosure for CVE-2025-56526 and CVE-2025-56527 — Stored XSS via unsanitized PDF content rendering and plaintext credential exposure in…

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

A Slack bot phishing framework for Red Teaming exercises