
wifi-agent
Rogue access point tool for creating captive portals, phishing credentials via cloned login pages, and injecting malware downloads for educational…

Rogue access point tool for creating captive portals, phishing credentials via cloned login pages, and injecting malware downloads for educational…

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

All the deals for InfoSec related software/tools this Black Friday

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Generates obfuscated VBA macros with AV/sandbox evasion for command execution payloads, supporting domain, disk, memory, and process checks.

Weaponized Browser-in-the-Middle (BitM) for Penetration Testers

Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

The SteaLinG is an open-source penetration testing framework designed for social engineering

it is malicious technique used by hackers to hide malware payloads in an encoded script in a specially crafted HTML attachment or web page

A proof of concept crypto virus to spread user awareness about attacks and implications of ransomwares. Phirautee is written purely using PowerShell…

A basic phishing kit scanner for dedicated and semi-dedicated hosting

Actively hunt for attacker infrastructure by filtering Shodan results with URLScan data.


WITCHCRAFT is a cyberdeck toolkit built for runners who dive deep into the mesh. It’s your all-in-one rig for data-ghosting, ICE-breaking, and…

Node.js command-and-control server with FUD payload generation, encrypted communication, session management, and modules for data exfiltration and…

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…