
ClickOnceBlobber
Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading a C# port of…

Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading a C# port of…

High-performance username search engine written in Go. Scans hundreds of social networks and websites to discover accounts associated with a given…

Real-time phishing platform that bypasses 2FA via a live noVNC browser session, capturing cookies, saved passwords, browsing history, and downloaded…

Cartero - Social Engineering Framework

Information gathering framework for phone numbers

An automated phishing tool with 30+ templates. This Tool is made for educational purpose only ! Author will not be responsible for any misuse of this…

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…


HTML/CSS/JS templates for Browser-In-The-Browser phishing attacks, embedding fake login windows with customizable titles, domains, and phishing links…

This is Advance Phishing Tool ! OTP PHISHING

OSINT tool that scrapes Twitter profile metadata to analyze activity patterns, timezone, language, geolocation, hashtags, and social connections for…

Remote operations commands implemented using Beacon Object Files

A multi-purpose OSINT toolkit with a neat web-interface.


PHP library for executing Telegram OSINT scenarios: search users, parse group members, monitor online status, download photos, and track profile…

Technical write-up and proof-of-concept for CVE-2022-44666, a Windows Contacts syslink control href attribute escape vulnerability enabling remote…

MCP server for Google search and page fetching using headless Chromium