
InfraGuard
InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution

InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution


Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

This is a proof-of-work for abusing git's clean filter against IDEs & Sublime.

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

CVE-2023-21716 - Microsoft Word RTF fonttbl Heap Corruption RCE exploit with reverse shell payload

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

⭐️The famous XWorm RAT, version 2.1. Educational purposes only

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…


A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

a SET framework templates


Chamilo-LMS (v2.0) CVE-2025-26153

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.