
SocialFishMobile
📱 🐟 An app to remote control SocialFish.

📱 🐟 An app to remote control SocialFish.

Exploit for CVE-2022-27226

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.


Remote operations commands implemented using Beacon Object Files

This is a Automated Generate Payload for CVE-2019-11932 (WhatsApp Remote Code Execution)

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

A unified console to perform the "kill chain" stages of attacks.

Use a Fake image.jpg to exploit targets (hide known file extensions)

A tool to transform Chromium browsers into a C2 Implant

Collection of scripts to aid in delivering payloads via Office Macros. Most are python. See http://khr0x40sh.wordpress.com for details.

Spoof SSDP replies and create fake UPnP devices to phish for credentials and NetNTLM challenge/response.

A simple script to generate a hidden url for social engineering.

PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

Addressbar spoofing through blob URL (Firefox browser). An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by…

EmailXpose is an open source AI-powered email security system that detects phishing, spam, scams, malware, and social engineering attacks. It goes…

POC Jamovi <=1.6.18 is affected by a cross-site scripting (XSS) vulnerability. The column-name is vulnerable to XSS in the ElectronJS Framework. An…

using the use of CVE-2026-0776 discord "asks" for admin allowing a cmd to be opened as admin