


"Bob the Smuggler": A tool that leverages HTML Smuggling Attack and allows you to create HTML files with embedded 7z/zip archives. The tool would…

Powerglot encodes offensive powershell scripts using polyglots . Offensive security tool useful for stego-malware, privilege escalation, lateral…

This is the development tree. Production downloads are at:

A payload delivery system which embeds payloads in an executable's icon file!

PoC - Exploit Delivery via Steganography and Polyglots, CVE-2014-0282

A collection of awesome penetration testing resources, tools and other shiny things

Encodes a PowerShell script in the pixels of a PNG file and generates a oneliner to execute

A list of Capture The Flag (CTF) frameworks, libraries, resources and software for started/experienced CTF players 🚩

PyExfil — Python 3 toolkit for researching and stress-testing data exfiltration techniques across network, physical, and steganographic channels. For…

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing. Project Onyx is a PoC Red Team pipeline designed to demonstrate advanced evasion…

A simple utility to convert EXE files to JPEG images and vice versa.

PEGASUS-NEO is a comprehensive penetration testing framework designed for security professionals and ethical hackers. It combines multiple security…


Exploit script for CVE-2021-27211

Curated reading list and taxonomy of attack and defense research for mobile on-device AI systems, covering adversarial, backdoor, model stealing, and…