hoodoer / JS-Tap
JavaScript payload and supporting software to be used as XSS payload or post exploitation implant to monitor users as they use the targeted application. Also includes a C2 for executing custom JavaScript payloads in clients, and a "mimic" feature that automatically generates custom payloads.
☆353Updated 2 months ago
Alternatives and similar repositories for JS-Tap:
Users that are interested in JS-Tap are comparing it to the libraries listed below
- Session Hijacking Visual Exploitation☆196Updated last year
- A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.☆390Updated 2 months ago
- Microsoft SharePoint Server Elevation of Privilege Vulnerability☆230Updated last year
- Everything and anything related to password spraying☆132Updated 10 months ago
- ☆166Updated 6 months ago
- A tool to generate a wordlist from the information present in LDAP, in order to crack passwords of domain accounts.☆350Updated last month
- Leak of any user's NetNTLM hash. Fixed in KB5040434☆250Updated 7 months ago
- ☆279Updated 3 weeks ago
- SoaPy is a Proof of Concept (PoC) tool for conducting offensive interaction with Active Directory Web Services (ADWS) from Linux hosts.☆170Updated last month
- Repository to store exploits created by Assetnotes Security Research team☆176Updated last year
- Weaponized Browser-in-the-Middle (BitM) for Penetration Testers☆467Updated 4 months ago
- Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC☆159Updated last year
- A Slack bot phishing framework for Red Teaming exercises☆166Updated 10 months ago
- A rapid HTTP downgrade smuggling scanner written in Go.☆253Updated 10 months ago
- Azure mindmap for penetration tests☆179Updated last year
- Offensive MSSQL toolkit written in Python, based off SQLRecon☆201Updated 2 months ago
- ☆81Updated 8 months ago
- Leveraging GitHub Actions to rotate IP addresses during password spraying attacks to bypass IP-Based blocking☆141Updated 10 months ago
- KnowsMore is a swiss army knife tool for pentesting Microsoft Active Directory (NTLM Hashes, BloodHound, NTDS and DCSync).☆220Updated 7 months ago
- ☆291Updated last year
- ☆285Updated last week
- Slides and Codes used for the workshop Red Team Infrastructure Automation☆180Updated 11 months ago
- Tool to automatically exploit Active Directory privilege escalation paths shown by BloodHound☆532Updated 4 months ago
- Python script to enumerate valid Microsoft 365 domains, retrieve tenant name, and check for an MDI instance.☆192Updated 4 months ago
- A Red Team Activity Hub☆199Updated last week
- ☆141Updated 4 months ago
- ☆531Updated 11 months ago
- Password spraying tool and Bloodhound integration☆229Updated 2 months ago
- SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens☆154Updated 3 months ago
- ☆139Updated 11 months ago