
KittyStager
KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

KittyStager is a simple stage 0 C2. It is made of a web server to host the shellcode and an implant, called kitten. The purpose of this project is to…

Rosemary: Cross-platform kernel-level pivoting over QUIC. No TUN/TAP. No proxychains. No proxy settings.

Uses Shodan API to pull down C2 servers to run known exploits on them.

Joomla 3.7 SQL injection (CVE-2017-8917)

Passive subdomain discovery tool that aggregates results from multiple online sources via CLI, supporting stdin/stdout, JSONL output, and API key…

PowerShell tool for enumerating Azure AD users, devices, applications, and domains via Microsoft Graph API, with offline data export capability.

A fast, simple, recursive content discovery tool written in Rust.

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Semantic search over videos using Gemini Embedding 2 or Qwen3-VL.

A simple FOFA client written in JavaFX. Made by WgpSec, Maintained by f1ashine.

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

Modular attack toolkit exploiting Azure DevOps REST API for reconnaissance, privilege escalation, and persistence using stolen cookies or PATs.

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

This C# tool sprays for admin access over the entire domain

Simple IP Information Tools for Reputation Data Analysis

Simple Automation script for juniper cve-2023-36845

A simple PoC for Atlassian Bitbucket RCE [CVE-2022-36804]