
LaZagne
Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Real-time phishing platform that bypasses 2FA via a live noVNC browser session, capturing cookies, saved passwords, browsing history, and downloaded…

PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

CVE-2023-24055 PoC (KeePass 2.5x)

This tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to…

Extracting Clear Text Passwords from mstsc.exe using API Hooking.

Clone and import Chromium cookies and passwords across browsers with offline DPAPI state key decryption, supporting AES-256 GCM encrypted databases…

An Advanced C# .NET Rat, It’s Stable and Contains Many Features.

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Jam all wifi clients/routers.

Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…

Chromepass - Hacking Chrome Saved Passwords

SensePost's modified hostapd for wifi attacks.

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

Continuously jam all wifi clients/routers

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…