

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

Stored Cross-Site Scripting (XSS) in osTicket via Vulnerable Bootstrap Tooltip Component


Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

An active cyber defense & honeypot system for OpenWrt routers running from a USB drive.

⭐️The famous XWorm RAT, version 2.1. Educational purposes only

cve-2024-21413

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...


Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens

Chamilo-LMS (v2.0) CVE-2025-26153

Track the GPS location of the user's smartphone or PC and capture a picture of the target, along with IP and device information.

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

Phantom Keylogger is an advanced, stealth-enabled keystroke and visual intelligence gathering system.