
skills
Reusable offensive security skills and plugins for AI agents, covering reconnaissance, exploitation, C2, payload development, and reporting across…

Reusable offensive security skills and plugins for AI agents, covering reconnaissance, exploitation, C2, payload development, and reporting across…

Weaponized Browser-in-the-Middle (BitM) for Penetration Testers

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

Resources to learn more about Chinese-language cybercrime actors.

EmailXpose is an open source AI-powered email security system that detects phishing, spam, scams, malware, and social engineering attacks. It goes…

Modlishka. Reverse Proxy.

Spoof file icons and extensions in Windows

Educational trojan simulator for cybersecurity training, simulating phishing attacks with social engineering, system reconnaissance, anti-sandbox…

A collection of awesome penetration testing resources and tools

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

Tool made to automate tasks of pentesting.

Educational cybersecurity project demonstrating exploitation and mitigation of CVE-2020-25213 (WordPress File Manager Plugin RCE). Includes malware…

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

Backdooring Claude Code via hooks in settings.json. Authorized use only!

Proof-of-concept security demo illustrating how PowerShell can create trusted-looking Windows toast notifications chained together with…

Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.

A comprehensive security toolkit with 1000+ penetration testing and security assessment tools.

Practical labs, notes, and reports for CEH v13 modules — covering web hacking, network pentesting, malware analysis, social engineering, and security…