
ExifSmugglingPoC
A Proof-of-Concept using Cache Smuggling + Exif data to passively download a second stage payload

A Proof-of-Concept using Cache Smuggling + Exif data to passively download a second stage payload

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Open Source Intelligence Interface for Deep Web Scraping

Automated OSINT framework for reconnaissance, data harvesting, and threat intelligence gathering with modular crawlers, scanners, and extraction…

TrevorC2 is a legitimate website (browsable) that tunnels client/server communications for covert command execution.

CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept

Uscrapper Vanta: Dive deeper into the web with this powerful open-source tool. Extract valuable insights with ease and efficiency, from both surface…

An OSINT tool that helps detect members of a company with leaked credentials

Extract data from modern Chrome versions, including refresh tokens, cookies, saved credentials, autofill data, browsing history, and bookmarks

Surreptitiously exfiltrate data from the browser over DNS

Content hijacking proof-of-concept using Flash, PDF and Silverlight

A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.

Quickjack is a point-and-click tool for intuitively producing advanced clickjacking and frame slicing attacks.

An open source swiss army knife for arbitrary communication over application protocols


Dumping App Bound Protected Credentials & Cookies Without Privileges.
