
beef
The Browser Exploitation Framework Project

The Browser Exploitation Framework Project

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…


Educational Telegram phishing simulation for cybersecurity training and awareness. Demonstrates credential harvesting via fake login pages in…

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Educational Android (Termux) toolkit for learning penetration testing, OSINT, social engineering, and network security through hands-on scripts,…

Phishing simulation and awareness framework for node-based campaigns, credential capture, SMTP delivery, CAPTCHA, and optional browser credential…

A fork of the great TokenTactics with support for CAE and token endpoint v2

MCP server for Google search and page fetching using headless Chromium

Modlishka. Reverse Proxy.

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

Documentation of my hands-on lab Moniker Link (CVE-2024-21413) completed on TryHackMe.

Spoof file icons and extensions in Windows

TryHackMe Moniker Link (CVE-2024-21413) walkthrough: Outlook Protected View bypass leading to NTLMv2 hash capture via a crafted moniker link.

Proof-of-concept for CVE-2026-22005 showing OAuth 2.0 device code phishing via too-short polling interval, with vulnerable Flask server and exploit…