hoodoer / JS-Tap
JavaScript payload and supporting software to be used as XSS payload or post exploitation implant to monitor users as they use the targeted application. Also includes a C2 for executing custom JavaScript payloads in clients, and a "mimic" feature that automatically generates custom payloads.
☆360Updated 2 weeks ago
Alternatives and similar repositories for JS-Tap:
Users that are interested in JS-Tap are comparing it to the libraries listed below
- Session Hijacking Visual Exploitation☆198Updated last year
- ☆328Updated this week
- ☆537Updated last year
- Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC☆154Updated last year
- ☆298Updated last month
- Offensive MSSQL toolkit written in Python, based off SQLRecon☆201Updated 3 months ago
- Remote Kerberos Relay made easy! Advanced Kerberos Relay Framework☆583Updated 10 months ago
- Microsoft SharePoint Server Elevation of Privilege Vulnerability☆231Updated last year
- Leak of any user's NetNTLM hash. Fixed in KB5040434☆255Updated 8 months ago
- A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.☆395Updated 3 months ago
- Everything and anything related to password spraying☆134Updated 11 months ago
- Tool to automatically exploit Active Directory privilege escalation paths shown by BloodHound☆548Updated 5 months ago
- Multiplayer pivoting solution☆371Updated 3 weeks ago
- A tool to generate a wordlist from the information present in LDAP, in order to crack passwords of domain accounts.☆352Updated 2 months ago
- Lab used for workshop and CTF☆179Updated 3 months ago
- SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens☆157Updated 5 months ago
- ☆298Updated 2 months ago
- Password spraying tool and Bloodhound integration☆232Updated 4 months ago
- peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.☆174Updated 3 weeks ago
- ☆139Updated last year
- A Slack bot phishing framework for Red Teaming exercises☆166Updated last year
- Azure mindmap for penetration tests☆181Updated last year
- SoaPy is a Proof of Concept (PoC) tool for conducting offensive interaction with Active Directory Web Services (ADWS) from Linux hosts.☆217Updated 2 months ago
- A rapid HTTP downgrade smuggling scanner written in Go.☆255Updated 11 months ago
- Different methods to get current username without using whoami☆174Updated last year
- Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultan…☆216Updated last year
- Weaponized Browser-in-the-Middle (BitM) for Penetration Testers☆494Updated 5 months ago
- ☆82Updated 3 weeks ago
- The GPOddity project, aiming at automating GPO attack vectors through NTLM relaying (and more).☆300Updated 5 months ago
- Reverse shell that can bypass windows defender detection☆165Updated last year