
Chamemask
Fake identity generator. 102 countries, one HTML file, no setup.

Fake identity generator. 102 countries, one HTML file, no setup.

Automated WPA/WPA2 phishing tool that captures handshakes, spawns a rogue access point, and lures users to a captive portal to harvest credentials…

Weaponized Browser-in-the-Middle (BitM) for Penetration Testers

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

EmailXpose is an open source AI-powered email security system that detects phishing, spam, scams, malware, and social engineering attacks. It goes…

Educational Telegram phishing simulation for cybersecurity training and awareness. Demonstrates credential harvesting via fake login pages in…

MCP server for Google search and page fetching using headless Chromium

Modlishka. Reverse Proxy.

Spoof file icons and extensions in Windows

Curated list of OSINT tools for offensive security, covering email harvesting, subdomain enumeration, threat intelligence, and social engineering for…

PoC exploit for CVE-2023-52076 - zip-slip path traversal in Atril/Xreader (MATE/Cinnamon) enabling arbitrary file write and RCE via crafted EPUB.…

Accurately Locate Smartphones using Social Engineering

CVE-2024-3094 XZ Utils backdoor research - attack surface visualiser, system vulnerability checker, and general Linux CVE assessment tool

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

FBIntelPy is a Python-based Facebook intelligence search tool. This tool assists in generating filtered Facebook URLs, which is particularly useful…

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

Educational cybersecurity project demonstrating exploitation and mitigation of CVE-2020-25213 (WordPress File Manager Plugin RCE). Includes malware…