
Deep-Live-Cam
real time face swap and one-click video deepfake with only a single image

real time face swap and one-click video deepfake with only a single image

Modlishka. Reverse Proxy.

Python-Based Pentesting Framework

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

Spoof file icons and extensions in Windows

Security awareness training tool for authorized phishing simulations and internal IT audits


Trojanize your payload - WinRAR (SFX) automatization - under Linux distros

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

it is malicious technique used by hackers to hide malware payloads in an encoded script in a specially crafted HTML attachment or web page

Credsleaker allows an attacker to craft a highly convincing credentials prompt using Windows Security, validate it against the DC and in turn leak it…

Educational proof-of-concept demonstrating how to embed a Meterpreter backdoor into a PDF file exploiting CVE-2010-1240, with step-by-step Metasploit…

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

A python server tool based on flask , this tool can phish some Facebook credentials!

A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formats.…

PowerShell proof-of-concept for CVE-2023-23397 that exploits Outlook's ReminderSoundFile property to intercept Net-NTLMv2 hashes via SMB or WebDAV…

Proof-of-concept exploit for stored XSS vulnerability in VanillaForum 2.6.3, demonstrating arbitrary HTML/script injection via insufficient input…

Project that brings together several pentest tools