DumpBrowserSecrets – Browser Credential Harvesting with App-Bound Encryption...
DumpBrowserSecrets extracts saved passwords, cookies, OAuth tokens and autofill data from Chrome, Edge, Firefox, Opera and Vivaldi, bypassing App-Bound Encryption via Early Bird APC injection.
View ArticleSmbCrawler – SMB Share Discovery and Secret-Hunting
SmbCrawler is a credentialed SMB share crawler for red teams that discovers misconfigured shares and hunts secrets across Windows networks.
View ArticleReconnoitre – Open-Source Reconnaissance and Service Enumeration Tool
Reconnoitre automates network reconnaissance and service enumeration for penetration testers and red teams using structured, repeatable workflows.
View ArticleScanners-Box – Open-Source Reconnaissance and Scanning Toolkit
Scanners-Box is an open-source reconnaissance and scanning toolkit for red teams and security researchers. Curated collection of scanners and recon utilities.
View Articlegitlab-runner-research – PoC for abusing self-hosted GitLab runners
gitlab-runner-research: PoC scripts demonstrating abuse of self-hosted GitLab runners and practical hardening and detection guidance.
View ArticleReaper – Unified Application Security Testing with AI Support
Reaper – an open-source AppSec testing framework combining recon, proxying, fuzzing and AI-agent workflows for penetration testers and red teams.
View ArticleNetExec – Network Execution Toolkit for Windows and Active Directory
NetExec provides multi-protocol network execution for Windows Active Directory environments. Install, run and use nxc for lateral movement, enumeration and command execution.
View ArticleHoneyBee – Misconfigured App Generator for Red Team Validation
HoneyBee generates intentionally misconfigured Docker environments and Nuclei templates using LLMs so red teams can rehearse exploitation and validate detection.
View ArticleAutoswagger – Automated discovery and testing of OpenAPI & Swagger endpoints
Autoswagger finds and tests OpenAPI/Swagger specs to expose unauthenticated endpoints, PII leaks and secrets. Tooling, installation and an attack scenario included.
View ArticleRustRedOps – Rust Native Offensive Toolkit Collection for Red Teams
RustRedOps is a collection of Rust-based offensive security modules for post-exploitation, process injection and payload staging, useful for red teams and penetration testers.
View ArticleHexStrike AI – Multi-Agent LLM Orchestration for Automated Offensive Security
HexStrike AI orchestrates LLM agents to run 150+ offensive security tools, automating reconnaissance, exploit selection and campaign execution.
View Articlethermoptic – Chrome-perfect HTTP Fingerprint Cloaking for Red Team Web Ops
thermoptic is a stealth proxy that makes curl and other clients look identical to Chrome across TCP, TLS and HTTP layers, bypassing JA3/JA4+ detection.
View Articleasnip – ASN Reconnaissance via Domain and IP Mapping
asnip maps domains and IPs to their Autonomous System Numbers (ASNs), retrieves CIDRs, and converts them into IPs for reconnaissance.
View ArticleBlockEDRTraffic – EDR Evasive Lateral Movement Tool
BlockEDRTraffic blocks Endpoint Detection and Response telemetry with Windows Firewall or Windows Filtering Platform to create brief stealth windows for red teams.
View ArticleRedExt – Browser Extension-Based C2 Framework for Red Team Recon
RedExt turns Chromium into a browser-based C2 agent, collect cookies, DOM, screenshots, clipboard, system data via a Flask server and Chrome extension.
View ArticleAzureStrike – Offensive Toolkit for Attacking Azure Active Directory...
AzureStrike is a red team toolkit for attacking Azure Active Directory, enabling reconnaissance, credential abuse, and persistence in cloud environments.
View ArticleChromeAlone – Chromium Browser C2 Implant for Red Team Operations
ChromeAlone turns Chromium into a stealthy C2 implant with credential capture, file access, and persistence. A browser-based alternative to Cobalt Strike.
View ArticleMailSniper – PowerShell Tool for Exchange Mailbox Search and Credential...
MailSniper PowerShell tool for Microsoft Exchange. Search mailboxes for passwords, network intel, and harvest usernames in red team operations.
View Articlexsshunter-express – Self-Hosted Blind XSS Payload Capture and Analysis
Self-hosted blind XSS hunter via Docker. Deploy xsshunter‑express in five minutes to capture stealthy XSS payloads with screenshots, DOM dumps, and full context.
View ArticleBrainDamage – Payload Generator and Encrypted Shell Stager for Red Teams
Generate and stage encrypted payloads with BrainDamage, a flexible toolkit for red teamers focused on stealth, staging, and remote command delivery.
View Article