JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and maintain persistence. Browser extension, electron app, and node/bun app implants are included.
☆478Jul 9, 2026Updated 2 months ago
Alternatives and similar repositories for JS-Tap
Users that are interested in JS-Tap are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ↕️🤫 Stealth redirector for your red team operation security☆1,108Jul 20, 2026Updated 2 months ago
- Leverage a legitimate WFP callout driver to prevent EDR agents from sending telemetry☆478Aug 2, 2024Updated 2 years ago
- Two new offensive techniques using Windows Fibers: PoisonFiber (The first remote enumeration & Fiber injection capability POC tool) Phan…☆285Sep 18, 2024Updated 2 years ago
- A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the …☆1,904Nov 3, 2024Updated last year
- BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions☆361Nov 19, 2024Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A beacon object file implementation of PoolParty Process Injection Technique.☆458Dec 21, 2023Updated 2 years ago
- .NET assembly loader with patchless AMSI and ETW bypass☆389Apr 19, 2023Updated 3 years ago
- ☆571Mar 28, 2024Updated 2 years ago
- An App Domain Manager Injection DLL PoC on steroids☆238Dec 14, 2023Updated 2 years ago
- PoC module to demonstrate automated lateral movement with the Havoc C2 framework.☆313Dec 9, 2023Updated 2 years ago
- PrivKit is a simple beacon object file that detects privilege escalation vulnerabilities caused by misconfigurations on Windows OS.☆621Jan 20, 2026Updated 8 months ago
- Load a dynamic library from memory by modifying the native Windows loader☆308May 5, 2026Updated 4 months ago
- Shellcode encryptor & obfuscator tool☆1,042Jul 21, 2026Updated 2 months ago
- Ghosting-AMSI☆249Apr 24, 2025Updated last year
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- WindowSpy is a Cobalt Strike Beacon Object File meant for automated and targeted user surveillance.☆286Feb 24, 2025Updated last year
- ☆347Jun 24, 2026Updated 2 months ago
- Dump cookies and credentials directly from Chrome/Edge process memory☆1,501Apr 9, 2026Updated 5 months ago
- A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techni…☆1,418Oct 27, 2023Updated 2 years ago
- Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).☆605Mar 19, 2024Updated 2 years ago
- Spartacus DLL/COM Hijacking Toolkit☆1,083Feb 1, 2024Updated 2 years ago
- Collection of UAC Bypass Techniques Weaponized as BOFs☆663Feb 21, 2024Updated 2 years ago
- A proof of concept demonstrating the DLL-load proxying using undocumented Syscalls.☆410Jan 11, 2026Updated 8 months ago
- Cobalt Strike UDRL for memory scanner evasion.☆1,032Jun 4, 2024Updated 2 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling☆1,292Mar 19, 2025Updated last year
- C++ self-Injecting dropper based on various EDR evasion techniques.☆444Feb 11, 2024Updated 2 years ago
- Chrome browser extension-based Command & Control☆270Mar 18, 2026Updated 6 months ago
- DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced (the …☆577Jun 5, 2023Updated 3 years ago
- BOF to steal browser cookies & credentials☆573Jul 23, 2026Updated 2 months ago
- A memory-based evasion technique which makes shellcode invisible from process start to end.☆1,200Oct 16, 2023Updated 2 years ago
- a tool to help operate in EDRs' blind spots☆775Dec 2, 2024Updated last year
- BadExclusionsNWBO is an evolution from BadExclusions to identify folder custom or undocumented exclusions on AV/EDR☆75Feb 9, 2024Updated 2 years ago
- Dynamically convert an unmanaged EXE or DLL file to PIC shellcode by prepending a shellcode stub.☆325Apr 12, 2024Updated 2 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Abusing Azure services over C2☆382Jan 20, 2026Updated 8 months ago
- Terminate AV/EDR Processes using kernel driver☆352Jun 12, 2023Updated 3 years ago
- Collection of Beacon Object Files (BOF) for Cobalt Strike☆714Sep 9, 2026Updated 2 weeks ago
- A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.☆640Jan 2, 2025Updated last year
- SOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Dire…☆899Feb 3, 2024Updated 2 years ago
- Positional Independent Code to extract clear text password from mstsc.exe using API Hooking via HWBP.☆249Jun 11, 2024Updated 2 years ago
- Generate an obfuscated DLL that will disable AMSI & ETW☆335Jul 15, 2024Updated 2 years ago