
Cuteit
IP obfuscator made to make a malicious ip a bit cuter

IP obfuscator made to make a malicious ip a bit cuter

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

Node.js command-and-control server with FUD payload generation, encrypted communication, session management, and modules for data exfiltration and…

PoC (Proof of Concept) de la CVE-2024-4367 - Vulnérabilité RCE dans libwebp. Démonstration complète incluant : création de payloads, scénarios…

Proof-of-concept exploit for CVE-2018-25031 (Swagger UI XSS) that exfiltrates authorization codes via crafted configUrl/url parameters.

The Browser Exploitation Framework Project

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

Payload Generation Framework

evilginx3 + gophish

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

Modified CVE-2022-30190 exploit tool for MS-MSDT Office RCE with custom docx template support, binary/command execution modes, and embedded HTTP…

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

POC CVE-2022-30190 : CVE 0-day MS Offic RCE aka msdt follina

Windows Remote Post Breach Tool via Telegram

CVE-2022-30190 | MS-MSDT Follina One Click