🏆 by drapl0n April 08, 2022
Bash Bunny Execution
screenGrab payload captures snapshots of target's screen periodically and store them into bunny.
🏆 by TW-D March 29, 2022
OMG Remote Access
1. Adds a user account (OMG_User:OMG_P@ssW0rD).
2. Adds this local user to local administrator group.
3. Shares "C:" directory (OMG_SHARE).
4. Adds a rule to...
🏆 by 0i41E March 23, 2022
General OMG
A small message box, telling the user that he violated the security policy. The hostname of the user will be send to a webhook to report the incident. Fill i...
🏆 by Cribbit March 16, 2022
Bash Bunny General
Downloads a list of Hak5 vids from YouTube (about 15 in the rss feed).
Then pick one at random, then opens it in the browser.
🏆 by Maker March 13, 2022
Credentials USB Rubber Ducky
A variant of Win_Pass_Grabber by makozort but not reliant on Internet potentially ignoring any server-side-issues with Downloading/Uploading Files and Logs.
🏆 by drapl0n March 07, 2022
Bash Bunny Credentials
Keylogger which sends each and every keystroke of target remotely/locally.
Features:
- Live keystroke capturing.
- Detailed key logs.
...
🏆 by Matthew Kayne March 01, 2022
Exfiltration USB Rubber Ducky
Sends any command output to an iMessage receiving number (this example grabs the devices IP)
🏆 by drapl0n February 14, 2022
Credentials USB Rubber Ducky
DuckyLogger is a Key Logger which captures every key stroke of target and send them to attacker.
- Live keystroke capturing.
- Detailed key logs.
- Persiste...
🏆 by TW-D February 07, 2022
Key Croc Recon
Ports Scanning with Nmap.
🏆 by 0i41E February 02, 2022
Bash Bunny Credentials
This payload will run an obfuscated script to dump user hashes. If you don't trust this obfuscated .bat file, you should run it within a save space first - w...
🏆 by Cribbit February 01, 2022
Mobile-Android USB Rubber Ducky
Forwards the last received email. Included are two versions one for Gmail and Samsung Email app this was tested on a S10 as there are many flavours of androi...
🏆 by 0i41E January 31, 2022
Remote Access USB Rubber Ducky
UDP Reverse shell executed in the background. Might create a firewall pop up, but will execute anyway.
🏆 by TW-D January 29, 2022
Bash Bunny Execution
This is a version of the PwnKit Vulnerability Local Privilege Escalation containing pre-compiled binaries for x86_64 Linux. If you don't want to use the p...
🏆 by TW-D January 29, 2022
Bash Bunny Execution
The Qualys Research Team has discovered a memory corruption vulnerability in polkit’s pkexec, a SUID-root program that is installed by default on every ma...
🏆 by 0i41E January 19, 2022
Key Croc Remote Access
This payload will give you screen access to your victims machine. Combined with KeyCrocs ability to type in commands, you have basically RemoteDesktop.
Setu...
🏆 by Cribbit January 19, 2022
General Key Croc
Play tic-tac-toe / noughts and crosses with the KeyCroc.
Open a text editor, start the game and enjoy.
How to play:
You move first.
Move the text cursor / ...
🏆 by @InfoSec_DrewZe January 14, 2022
Mobile-Android OMG Remote Access
Upload Malicious APK to Android Device with an OMG Cable. This script is for educational and pentesting purposes only! Use at your own risk!
🏆 by int0x80 January 14, 2022
Mobile-Android OMG Remote Access
Download and install an APK on Android
An OMG Cable payload which downloads and installs an APK onto an Android device. Here are the high-level notes.
I wo...