Quantcast
Channel: Darknet – Hacking Tools, Hacker News & Cyber Security
Browsing index pages (287 articles)

DumpBrowserSecrets – Browser Credential Harvesting with App-Bound Encryption...

DumpBrowserSecrets extracts saved passwords, cookies, OAuth tokens and autofill data from Chrome, Edge, Firefox, Opera and Vivaldi, bypassing App-Bound Encryption via Early Bird APC injection.

View Article


SmbCrawler – SMB Share Discovery and Secret-Hunting

SmbCrawler is a credentialed SMB share crawler for red teams that discovers misconfigured shares and hunts secrets across Windows networks.

View Article


Reconnoitre – Open-Source Reconnaissance and Service Enumeration Tool

Reconnoitre automates network reconnaissance and service enumeration for penetration testers and red teams using structured, repeatable workflows.

View Article

Scanners-Box – Open-Source Reconnaissance and Scanning Toolkit

Scanners-Box is an open-source reconnaissance and scanning toolkit for red teams and security researchers. Curated collection of scanners and recon utilities.

View Article

gitlab-runner-research – PoC for abusing self-hosted GitLab runners

gitlab-runner-research: PoC scripts demonstrating abuse of self-hosted GitLab runners and practical hardening and detection guidance.

View Article


Reaper – Unified Application Security Testing with AI Support

Reaper – an open-source AppSec testing framework combining recon, proxying, fuzzing and AI-agent workflows for penetration testers and red teams.

View Article

NetExec – Network Execution Toolkit for Windows and Active Directory

NetExec provides multi-protocol network execution for Windows Active Directory environments. Install, run and use nxc for lateral movement, enumeration and command execution.

View Article

HoneyBee – Misconfigured App Generator for Red Team Validation

HoneyBee generates intentionally misconfigured Docker environments and Nuclei templates using LLMs so red teams can rehearse exploitation and validate detection.

View Article


Autoswagger – Automated discovery and testing of OpenAPI & Swagger endpoints

Autoswagger finds and tests OpenAPI/Swagger specs to expose unauthenticated endpoints, PII leaks and secrets. Tooling, installation and an attack scenario included.

View Article


RustRedOps – Rust Native Offensive Toolkit Collection for Red Teams

RustRedOps is a collection of Rust-based offensive security modules for post-exploitation, process injection and payload staging, useful for red teams and penetration testers.

View Article

HexStrike AI – Multi-Agent LLM Orchestration for Automated Offensive Security

HexStrike AI orchestrates LLM agents to run 150+ offensive security tools, automating reconnaissance, exploit selection and campaign execution.

View Article

thermoptic – Chrome-perfect HTTP Fingerprint Cloaking for Red Team Web Ops

thermoptic is a stealth proxy that makes curl and other clients look identical to Chrome across TCP, TLS and HTTP layers, bypassing JA3/JA4+ detection.

View Article

asnip – ASN Reconnaissance via Domain and IP Mapping

asnip maps domains and IPs to their Autonomous System Numbers (ASNs), retrieves CIDRs, and converts them into IPs for reconnaissance.

View Article


BlockEDRTraffic – EDR Evasive Lateral Movement Tool

BlockEDRTraffic blocks Endpoint Detection and Response telemetry with Windows Firewall or Windows Filtering Platform to create brief stealth windows for red teams.

View Article

RedExt – Browser Extension-Based C2 Framework for Red Team Recon

RedExt turns Chromium into a browser-based C2 agent, collect cookies, DOM, screenshots, clipboard, system data via a Flask server and Chrome extension.

View Article


AzureStrike – Offensive Toolkit for Attacking Azure Active Directory...

AzureStrike is a red team toolkit for attacking Azure Active Directory, enabling reconnaissance, credential abuse, and persistence in cloud environments.

View Article

ChromeAlone – Chromium Browser C2 Implant for Red Team Operations

ChromeAlone turns Chromium into a stealthy C2 implant with credential capture, file access, and persistence. A browser-based alternative to Cobalt Strike.

View Article


MailSniper – PowerShell Tool for Exchange Mailbox Search and Credential...

MailSniper PowerShell tool for Microsoft Exchange. Search mailboxes for passwords, network intel, and harvest usernames in red team operations.

View Article

xsshunter-express – Self-Hosted Blind XSS Payload Capture and Analysis

Self-hosted blind XSS hunter via Docker. Deploy xsshunter‑express in five minutes to capture stealthy XSS payloads with screenshots, DOM dumps, and full context.

View Article

BrainDamage – Payload Generator and Encrypted Shell Stager for Red Teams

Generate and stage encrypted payloads with BrainDamage, a flexible toolkit for red teamers focused on stealth, staging, and remote command delivery.

View Article
Browsing index pages (287 articles)


Latest Images