π Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh
β4,116Jun 4, 2026Updated last month
Alternatives and similar repositories for malicious-pdf
Users that are interested in malicious-pdf are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and findinβ¦β7,897Jun 29, 2026Updated 3 weeks ago
- linWinPwn is a bash script that streamlines the use of a number of Active Directory toolsβ2,192Updated this week
- An OOB interaction gathering server and client libraryβ4,456Jul 15, 2026Updated last week
- ππ¦ Dalfox is a powerful open-source XSS scanner and utility focused on automation.β5,174Updated this week
- ScareCrow - Payload creation framework designed around EDR bypass.β2,891Aug 18, 2023Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer β’ AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.β3,480Jan 19, 2025Updated last year
- Rockyou for web fuzzingβ3,202Mar 11, 2026Updated 4 months ago
- A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.β6,697May 27, 2026Updated 2 months ago
- Automation for internal Windows Penetrationtest / AD-Securityβ3,686Aug 28, 2025Updated 10 months ago
- Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.β6,293Aug 14, 2024Updated last year
- One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password π‘οΈβ6,690Jul 9, 2026Updated 2 weeks ago
- A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formβ¦β1,188Jun 10, 2024Updated 2 years ago
- Collection of methodology and test case for various web vulnerabilities.β7,167Jun 25, 2025Updated last year
- Adversary Emulation Frameworkβ11,579Updated this week
- End-to-end encrypted email - Proton Mail β’ AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.β2,120Jul 9, 2026Updated 2 weeks ago
- All about bug bounty (bypasses, payloads, and etc)β6,815Sep 8, 2023Updated 2 years ago
- Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probingβ3,144Mar 7, 2026Updated 4 months ago
- This repo covers some code execution and AV Evasion methods for Macros in Office documentsβ1,275Jan 27, 2022Updated 4 years ago
- Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X!β2,695Jun 11, 2026Updated last month
- Contextual Content Discovery Toolβ3,234Jul 10, 2026Updated 2 weeks ago
- Privilege Escalation Enumeration Script for Windowsβ3,891Jul 15, 2026Updated last week
- A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.β2,297Apr 24, 2026Updated 3 months ago
- A toolkit for testing, tweaking and cracking JSON Web Tokensβ6,715May 1, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer β’ AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.β5,052Mar 20, 2026Updated 4 months ago
- reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Eβ¦β8,749Jul 13, 2026Updated 2 weeks ago
- evilginx3 + gophishβ2,016Jun 15, 2024Updated 2 years ago
- β1,704Apr 14, 2025Updated last year
- Awesome list of step by step techniques to achieve Remote Code Execution on various apps!β1,942Oct 7, 2023Updated 2 years ago
- A unique technique to execute binaries from a password protected zipβ1,034Jul 1, 2022Updated 4 years ago
- a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )β2,893Feb 27, 2026Updated 5 months ago
- evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)β1,505Dec 21, 2023Updated 2 years ago
- KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the defaultβ¦β1,652Aug 6, 2022Updated 3 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer β’ AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A fast, simple, recursive content discovery tool written in Rust.β7,961Apr 15, 2026Updated 3 months ago
- This map lists the essential techniques to bypass anti-virus and EDRβ3,367Mar 28, 2025Updated last year
- A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secretsβ1,575Mar 8, 2026Updated 4 months ago
- "Can I take over XYZ?" β a list of services and how to claim (sub)domains with dangling DNS records.β5,769Feb 8, 2025Updated last year
- HTTP parameter discovery suite.β6,366Feb 20, 2025Updated last year
- Hidden parameters discovery suiteβ2,086Sep 8, 2024Updated last year
- Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivyβs loader does this by β¦β743Aug 18, 2023Updated 2 years ago