
skills
Reusable offensive security skills and plugins for AI agents, covering reconnaissance, exploitation, C2, payload development, and reporting across…

Reusable offensive security skills and plugins for AI agents, covering reconnaissance, exploitation, C2, payload development, and reporting across…

Automated WPA/WPA2 phishing tool that captures handshakes, spawns a rogue access point, and lures users to a captive portal to harvest credentials…

Weaponized Browser-in-the-Middle (BitM) for Penetration Testers

Automated AI powered Facebook intelligence tool for target profiling, network analysis and threat reporting. Runs entirely on-device via Ollama.…

【Teedy 1.11】Account Takeover via XSS

Personally crafted Bash Bunny Payloads

Academy LMS <= 5.10 CSRF

Proof-of-concept scripts demonstrating reflected XSS in the Ultimate Classified Listings WordPress plugin and admin cookie theft via crafted payloads…

Case Study: SSHtranger Things (CVE-2019-6111, CVE-2019-6110) in Cisco SD-WAN

evilginx3 + gophish

Rogue access point toolkit for WiFi penetration testing, deploying evil portal phishing payloads to capture credentials and perform social…

FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule…

Ruby on Rails Phishing Framework

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

Proof-of-concept exploit for CVE-2022-48429, a stored cross-site scripting vulnerability in JetBrains YouTrack dashboards enabling low-privileged…

Exploit for CVE-2022-27226

Super organized and flexible script for sending phishing campaigns

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow