π Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh
β4,130Jun 4, 2026Updated 2 months ago
Alternatives and similar repositories for malicious-pdf
Users that are interested in malicious-pdf are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and findinβ¦β7,984Updated this week
- linWinPwn is a bash script that streamlines the use of a number of Active Directory toolsβ2,198Aug 8, 2026Updated last week
- An OOB interaction gathering server and client libraryβ4,483Updated this week
- ππ¦ Dalfox is a powerful open-source XSS scanner and utility focused on automation.β5,234Updated this week
- ScareCrow - Payload creation framework designed around EDR bypass.β2,891Aug 18, 2023Updated 2 years ago
- GPU virtual machines on DigitalOcean Gradient AI β’ AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.β3,482Jan 19, 2025Updated last year
- Rockyou for web fuzzingβ3,227Mar 11, 2026Updated 5 months ago
- A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.β6,708May 27, 2026Updated 2 months ago
- Automation for internal Windows Penetrationtest / AD-Securityβ3,690Aug 28, 2025Updated 11 months ago
- Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.β6,316Aug 7, 2026Updated last week
- One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password π‘οΈβ6,715Jul 9, 2026Updated last month
- A PoC that packages payloads into output containers to evade Mark-of-the-Web flag & demonstrate risks associated with container file formβ¦β1,204Jun 10, 2024Updated 2 years ago
- Collection of methodology and test case for various web vulnerabilities.β7,180Jun 25, 2025Updated last year
- Adversary Emulation Frameworkβ11,671Updated this week
- Deploy open-source AI quickly and easily - Special Bonus Offer β’ AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.β2,131Jul 9, 2026Updated last month
- All about bug bounty (bypasses, payloads, and etc)β6,827Sep 8, 2023Updated 2 years ago
- Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probingβ3,150Mar 7, 2026Updated 5 months ago
- This repo covers some code execution and AV Evasion methods for Macros in Office documentsβ1,276Jan 27, 2022Updated 4 years ago
- Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X!β2,719Jun 11, 2026Updated 2 months ago
- Contextual Content Discovery Toolβ3,239Jul 10, 2026Updated last month
- Privilege Escalation Enumeration Script for Windowsβ3,910Jul 15, 2026Updated last month
- A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.β2,305Apr 24, 2026Updated 3 months ago
- A toolkit for testing, tweaking and cracking JSON Web Tokensβ6,742May 1, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer β’ AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.β5,062Mar 20, 2026Updated 4 months ago
- reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Eβ¦β8,779Jul 13, 2026Updated last month
- evilginx3 + gophishβ2,022Jun 15, 2024Updated 2 years ago
- β1,704Apr 14, 2025Updated last year
- Awesome list of step by step techniques to achieve Remote Code Execution on various apps!β1,941Oct 7, 2023Updated 2 years ago
- A unique technique to execute binaries from a password protected zipβ1,033Jul 1, 2022Updated 4 years ago
- a tool for pentesters to help find delicious candy, by @l0ss and @Sh3r4 ( Twitter: @/mikeloss and @/sh3r4_hax )β2,908Feb 27, 2026Updated 5 months ago
- evasion technique to defeat and divert detection and prevention of security products (AV/EDR/XDR)β1,507Dec 21, 2023Updated 2 years ago
- KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the defaultβ¦β1,655Aug 6, 2022Updated 4 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits β’ AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- A fast, simple, recursive content discovery tool written in Rust.β8,015Apr 15, 2026Updated 4 months ago
- This map lists the essential techniques to bypass anti-virus and EDRβ3,431Mar 28, 2025Updated last year
- A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secretsβ1,584Mar 8, 2026Updated 5 months ago
- "Can I take over XYZ?" β a list of services and how to claim (sub)domains with dangling DNS records.β5,783Feb 8, 2025Updated last year
- HTTP parameter discovery suite.β6,380Feb 20, 2025Updated last year
- Hidden parameters discovery suiteβ2,089Sep 8, 2024Updated last year
- Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivyβs loader does this by β¦β743Aug 18, 2023Updated 2 years ago