
pwndrop
Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

Open Source Intelligence Interface for Deep Web Scraping

Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation…

强大的内网渗透辅助工具集-让Yasso像风一样 支持rdp,ssh,redis,postgres,mongodb,mssql,mysql,winrm等服务爆破,快速的端口扫描,强大的web指纹识别,各种内置服务的一键利用(包括ssh完全交互式登陆,mssql提权,redis一键利用,mysql数据库…

A better whois and domain intelligence toolkit

An SSL Enabled Basic Auth Credential Harvester with a Word Document Template URL Injector

ntlm relay attack to Exchange Web Services

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

Pastejacking - PasteZort

Search for information related to domain: Emails - IP addresses - Sub-Domains - Information on WEB technology - Type of Firewall - NS and MX records.

Frameless Browser‑in‑the‑Browser (BitB) - No iframes, no frame‑busting issues. A single‑script Shadow DOM / MutationObserver library for realistic…

A Ligolo-ng JavaScript agent working inside Chrome & Chromium-based browsers by leveraging Isolated Web Applications.

flash钓鱼源码 中文+英文

Scripts to clone CA certificates for use in HTTPS client attacks.

Gophish with Malicious Attachment and HTTP redirect support

.json and .yaml files used to exploit CVE-2018-25031

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…