
camjacking
CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

An email spoofing testing tool that aims to bypass SPF/DKIM/DMARC and forge DKIM signatures.🍻

ISeeYou is a Bash and Javascript tool to find the exact location of the users during social engineering or phishing engagements. Using exact location…

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

Dependency-free Python PoC generator for CVE-2025-24071 that crafts a malicious .library-ms file in a ZIP to trigger Windows Explorer NTLM hash…

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

Potential malicious code execution via CHM hijacking (CVE-2019-9896)

A Windows Remote Administration Tool in Visual Basic with UNC paths

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

Spoof emails from any of the +2 Million domains using MailChannels (DEFCON 31 Talk)

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

In LetterPress plugin <= 1.2.1 is vulnerable to Html Injection Vulnerability which can futher leads to Open Redirection Vulnerabilty.

Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

Scripts to clone CA certificates for use in HTTPS client attacks.

Emulates a Cisco ASA Anyconnect VPN service for credential harvesting and VBS payload delivery in red team phishing operations.