JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and maintain persistence. Browser extension, electron app, and node/bun app implants are included.
☆479Jul 9, 2026Updated last month
Alternatives and similar repositories for JS-Tap
Users that are interested in JS-Tap are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ↕️🤫 Stealth redirector for your red team operation security☆1,104Jul 20, 2026Updated last month
- Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry☆478Aug 2, 2024Updated 2 years ago
- Two new offensive techniques using Windows Fibers: PoisonFiber (The first remote enumeration & Fiber injection capability POC tool) Phan…☆286Sep 18, 2024Updated last year
- A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the …☆1,899Nov 3, 2024Updated last year
- BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions☆361Nov 19, 2024Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A beacon object file implementation of PoolParty Process Injection Technique.☆458Dec 21, 2023Updated 2 years ago
- .NET assembly loader with patchless AMSI and ETW bypass☆389Apr 19, 2023Updated 3 years ago
- An App Domain Manager Injection DLL PoC on steroids☆216Dec 14, 2023Updated 2 years ago
- ☆570Mar 28, 2024Updated 2 years ago
- PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.☆614Jan 20, 2026Updated 7 months ago
- Ghosting-AMSI☆251Apr 24, 2025Updated last year
- PoC module to demonstrate automated lateral movement with the Havoc C2 framework.☆314Dec 9, 2023Updated 2 years ago
- Load a dynamic library from memory by modifying the native Windows loader☆310May 5, 2026Updated 3 months ago
- Shellcode encryptor & obfuscator tool☆1,038Jul 21, 2026Updated last month
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- ☆346Jun 24, 2026Updated 2 months ago
- WindowSpy is a Cobalt Strike Beacon Object File meant for automated and targeted user surveillance.☆287Feb 24, 2025Updated last year
- A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techni…☆1,415Oct 27, 2023Updated 2 years ago
- Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).☆606Mar 19, 2024Updated 2 years ago
- Spartacus DLL/COM Hijacking Toolkit☆1,084Feb 1, 2024Updated 2 years ago
- Chrome browser extension-based Command & Control☆268Mar 18, 2026Updated 5 months ago
- Dump cookies and credentials directly from Chrome/Edge process memory☆1,496Apr 9, 2026Updated 4 months ago
- Cobalt Strike UDRL for memory scanner evasion.☆1,031Jun 4, 2024Updated 2 years ago
- Collection of UAC Bypass Techniques Weaponized as BOFs☆657Feb 21, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.☆412Jan 11, 2026Updated 7 months ago
- BOF to steal browser cookies & credentials☆574Jul 23, 2026Updated last month
- Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling☆1,291Mar 19, 2025Updated last year
- C++ self-Injecting dropper based on various EDR evasion techniques.☆447Feb 11, 2024Updated 2 years ago
- DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced (the …☆577Jun 5, 2023Updated 3 years ago
- A memory-based evasion technique which makes shellcode invisible from process start to end.☆1,200Oct 16, 2023Updated 2 years ago
- a tool to help operate in EDRs' blind spots☆774Dec 2, 2024Updated last year
- BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR☆76Feb 9, 2024Updated 2 years ago
- Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.☆327Apr 12, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Abusing Azure services over C2☆381Jan 20, 2026Updated 7 months ago
- Terminate AV/EDR Processes using kernel driver☆354Jun 12, 2023Updated 3 years ago
- Collection of Beacon Object Files (BOF) for Cobalt Strike☆713Jul 16, 2026Updated last month
- A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.☆639Jan 2, 2025Updated last year
- SOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Dire…☆901Feb 3, 2024Updated 2 years ago
- Just another C2 Redirector using CloudFlare. Support multiple C2 and multiple domains. Support for websocket listener.☆216Mar 14, 2025Updated last year
- Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP.☆251Jun 11, 2024Updated 2 years ago