
Embedded-PDF
This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

Use a Fake image.jpg to exploit targets (hide known file extensions)

Embed and hide any file in an HTML file

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

Hide your payload into .jpg file

A Phishing Dropper designed to Pentest.

Proof-of-concept exploit for CVE-2026-20841, a Windows Notepad remote code execution vulnerability, using a crafted .md file and social engineering…

Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure

Educational proof-of-concept demonstrating how to embed a Meterpreter backdoor into a PDF file exploiting CVE-2010-1240, with step-by-step Metasploit…

Weaponizes Selenium to automate credential theft, cookie dumping, email exfiltration, and file extraction from Chromium browsers for red team…

InfoHound is an OSINT to extract a large amount of data given a web domain name.

A security vulnerability has been identified in Krayin CRM <=2.1.0 that allows a low-privileged user to escalate privileges by tricking an admin into…

A quick handy script to harvest credentials off of a user during a Red Team and get execution of a file from the user

This project contains a Python script that exploits **CVE-2023-38831**, a vulnerability in **WinRAR** versions prior to 6.23. The exploit generates a…

PoC exploit for CVE-2023-52076 - zip-slip path traversal in Atril/Xreader (MATE/Cinnamon) enabling arbitrary file write and RCE via crafted EPUB.…

A practical chain that starts with an innocuous PDF file and ends up in a reverse shell on an AWS EC2 instance

HTML/CSS/JS templates for Browser-In-The-Browser phishing attacks, embedding fake login windows with customizable titles, domains, and phishing links…