
skyhook
A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.

A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.

Generates HTML smuggling pages that embed and reconstruct files client-side via JavaScript, with payload encoding, chunking, obfuscation, and…

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Ansible role that simulates a realistic CrushFTP CVE-2025-31161 exploitation scenario with rotating sensitive data files and automated defender…

Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection…

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

RDP client with extended control for automated mouse, keyboard, and clipboard manipulation, file transfer, SOCKS proxy, and remote command execution…

AV/EDR evasion via direct system calls.

Easy files and payloads delivery over DNS

Packs C# assemblies, PE files, or shellcode into encrypted Nim binaries with advanced evasion features including AMSI/ETW bypass, sandbox detection,…

DNS Exfiltration tool for stealthily sending files over DNS requests.

Real-time phishing platform that bypasses 2FA via a live noVNC browser session, capturing cookies, saved passwords, browsing history, and downloaded…

Packet injection for wifi; simplified.

BIG-IP iControl REST vulnerability CVE-2022-1388 PoC

A listener profile for the Mythic C2 framework that utilizes AI vendors file API's

Permanently disable EDRs as local admin