
Malicious-MCP
A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

A Proof-of-concept repository showing how an untrusted MCP server can steal literally everything...

Download pictures (or videos) along with their captions and other metadata from Instagram.

Get Keyboard,Mouse,ScreenShot,Microphone Inputs from Target Computer and Send to your Mail.

A Telegram Mass Surveillance Bot in Python

Real-time geospatial OSINT platform aggregating flight, vessel, and satellite data with dark web search, social media dorking, and AI-powered…

CloakifyFactory - Data Exfiltration & Infiltration In Plain Sight; Convert any filetype into list of everyday strings, using Text-Based…

OSINT Project. Collect information from a mail. Gather. Profile. Timeline.

An OSINT tool that helps detect members of a company with leaked credentials

Free email OSINT tool, 2500+ platforms, identity clustering, breach detection. No API keys required. pip install mailaccess

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

Weaponizes Selenium to automate credential theft, cookie dumping, email exfiltration, and file extraction from Chromium browsers for red team…

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

Simple Windows and Linux keystroke injection tool that exfiltrates stored WiFi data (SSID and password).

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

The SteaLinG is an open-source penetration testing framework designed for social engineering

Twitter Intelligence OSINT project performs tracking and analysis of the Twitter

PowerShell script that invokes legitimate credential prompts and exfiltrates captured passwords over DNS using CredentialPicker and Resolve-DnsName.