https://vimeo.com/1078790783/ed1c389243 Demo Preview π
This is a quick demo of my RAT in action.
I plan to add PureOS-CPC encryption soon.
Full release here on Telegram in 2-3 days!
This is a quick demo of my RAT in action.
I plan to add PureOS-CPC encryption soon.
Full release here on Telegram in 2-3 days!
Vimeo
HexSec Remote Administrator Tool (RAT) AV Evasion Windows Defender Bypass
Introducing a powerful Remote Administrator Tool (RAT) designed for seamless and efficient remote system management. This tool provides fast and reliable access to remote machines, ensuring smooth administration without interruptions. It features advancedβ¦
π10β€4
This media is not supported in your browser
VIEW IN TELEGRAM
Admin Panel Finder v1
A simple tool to help you discover admin panels on websites. Developed and maintained by the HexSec Community.
https://github.com/hexsecteam/admin-panel-finder
A simple tool to help you discover admin panels on websites. Developed and maintained by the HexSec Community.
https://github.com/hexsecteam/admin-panel-finder
β€7π4πΎ2
Linux Commands Every Cybersecurity Specialist Needs.pdf.pdf
9.8 MB
π Linux Security Commands & Forensics Handbook
Description
This handbook is a complete reference for mastering Linux security commands, digital forensics, and system monitoring. It combines practical one-liners, advanced scripting techniques, and investigation workflows to help cybersecurity professionals detect threats, analyze incidents, and harden systems.
Inside, youβll find command-driven methods for:
π Threat Detection: Identify crypto-mining malware, rootkits, suspicious processes, and network anomalies.
π§ͺ Forensic Analysis: Perform memory dumps, timeline reconstruction, file system investigations, and evidence preservation.
π System & Network Monitoring: Analyze CPU/memory usage, TCP/UDP connections, firewall logs, and packet captures with tcpdump and iptables.
π€ Account & Permission Auditing: Check password policies, SSH configurations, and privilege escalations.
βοΈ Automation & Scripting: Create reusable scripts for incident response and security auditing across multiple Linux distributions.
Description
This handbook is a complete reference for mastering Linux security commands, digital forensics, and system monitoring. It combines practical one-liners, advanced scripting techniques, and investigation workflows to help cybersecurity professionals detect threats, analyze incidents, and harden systems.
Inside, youβll find command-driven methods for:
π Threat Detection: Identify crypto-mining malware, rootkits, suspicious processes, and network anomalies.
π§ͺ Forensic Analysis: Perform memory dumps, timeline reconstruction, file system investigations, and evidence preservation.
π System & Network Monitoring: Analyze CPU/memory usage, TCP/UDP connections, firewall logs, and packet captures with tcpdump and iptables.
π€ Account & Permission Auditing: Check password policies, SSH configurations, and privilege escalations.
βοΈ Automation & Scripting: Create reusable scripts for incident response and security auditing across multiple Linux distributions.
π₯7β€4π2
Metasploit Advanced Techniques & Exploitation Mastery.pdf
2.1 MB
π‘οΈ Metasploit Framework: Advanced Techniques & Commands π―
Metasploit isnβt just a tool β itβs a powerful offensive security framework used by ethical hackers and penetration testers to simulate real-world attacks, validate defenses, and improve security posture.
π§ What Youβll Learn in Advanced Use:
π§° Advanced Modules & Features
β Post-exploitation tools (privilege escalation, keyloggers)
β Session handling with Meterpreter
β Database integration for managing targets
π‘ Automation & Scripting
β Resource scripts (.rc) to automate multi-step attacks
β AutoRun scripts for persistence
β Integration with tools like Nmap, Nessus, and Burp Suite
π― Evasion & Obfuscation
β Encoding payloads to bypass basic AV
β Using custom stagers, packers, and Veil
π‘ Network Pivoting & Tunneling
β Route traffic through compromised hosts
β Port forwarding and SOCKS proxies
π Exploit Customization
β Modify exploit modules
β Create custom payloads
β Use msfvenom for payload generation
Metasploit isnβt just a tool β itβs a powerful offensive security framework used by ethical hackers and penetration testers to simulate real-world attacks, validate defenses, and improve security posture.
π§ What Youβll Learn in Advanced Use:
π§° Advanced Modules & Features
β Post-exploitation tools (privilege escalation, keyloggers)
β Session handling with Meterpreter
β Database integration for managing targets
π‘ Automation & Scripting
β Resource scripts (.rc) to automate multi-step attacks
β AutoRun scripts for persistence
β Integration with tools like Nmap, Nessus, and Burp Suite
π― Evasion & Obfuscation
β Encoding payloads to bypass basic AV
β Using custom stagers, packers, and Veil
π‘ Network Pivoting & Tunneling
β Route traffic through compromised hosts
β Port forwarding and SOCKS proxies
π Exploit Customization
β Modify exploit modules
β Create custom payloads
β Use msfvenom for payload generation
β€15π₯3π1
OSCP CheatSheet.pdf
477.7 KB
π Level Up Your Pentesting Game! π‘οΈ
Get your hands on the Ultimate OSCP Cheat Sheet π β packed with commands, payloads, and resources for real-world hacking & OSCP prep!
π₯ Special Offer: Our SOC Playbook is now available at an exclusive discount! Perfect for anyone looking to sharpen their Security Operations skills.
Get your hands on the Ultimate OSCP Cheat Sheet π β packed with commands, payloads, and resources for real-world hacking & OSCP prep!
π₯ Special Offer: Our SOC Playbook is now available at an exclusive discount! Perfect for anyone looking to sharpen their Security Operations skills.
β€7π2π₯1
Top_50_Kali_Linux_Tools_Guide_for_Offensive_Professionals_pdf_20250818.pdf
3.8 MB
π Top 50 Kali Linux Tools Guide for Offensive Professionals β FREE PDF
Looking to level up your hacking and pentesting skills with Kali Linux? This comprehensive PDF is your go-to resource! From Nmap to Metasploit, and Burp Suite to John the Ripper β explore 50+ essential tools used by professional offensive security experts.
π₯ Whatβs Inside?
- Categorized tools for Reconnaissance, Exploitation, Post-Exploitation, and Reporting
-Real-world command examples for tools like Nmap, SQLMap, Aircrack-ng, Hydra, etc.
- Tips on ethical usage, lab setup, and best practices.
Looking to level up your hacking and pentesting skills with Kali Linux? This comprehensive PDF is your go-to resource! From Nmap to Metasploit, and Burp Suite to John the Ripper β explore 50+ essential tools used by professional offensive security experts.
π₯ Whatβs Inside?
- Categorized tools for Reconnaissance, Exploitation, Post-Exploitation, and Reporting
-Real-world command examples for tools like Nmap, SQLMap, Aircrack-ng, Hydra, etc.
- Tips on ethical usage, lab setup, and best practices.
β€14π₯1π1
π PassGen by HexSec
Generate smart wordlists on Termux using names, nicknames, teams & dates.
Automatically applies case styles, leetspeak, separators & numeric tails β saved into wordlist.txt.
π Get it here: github.com/hexsecteam/Passgen
β‘οΈ Quick install (Termux):
pkg update -y && pkg upgrade -y && pkg install -y python git && \
pip install rich && \
git clone github.com/hexsecteam/Passgen.git && \
cd passenger && python Passgen.py
Tutorial: https://youtube.com/shorts/5AHUQuLbBSM
Generate smart wordlists on Termux using names, nicknames, teams & dates.
Automatically applies case styles, leetspeak, separators & numeric tails β saved into wordlist.txt.
π Get it here: github.com/hexsecteam/Passgen
β‘οΈ Quick install (Termux):
pkg update -y && pkg upgrade -y && pkg install -y python git && \
pip install rich && \
git clone github.com/hexsecteam/Passgen.git && \
cd passenger && python Passgen.py
Tutorial: https://youtube.com/shorts/5AHUQuLbBSM
GitHub
GitHub - hexsecteam/Passgen: The main purpose is to generate custom wordlists based on user-provided info (name, surname, nicknameβ¦
The main purpose is to generate custom wordlists based on user-provided info (name, surname, nickname, team, date of birth, etc.). The tool automatically applies variations like case transformation...
β€4π₯3π₯°2
Creatively Malicious Prompt Engineering.pdf
3.4 MB
π Creatively Malicious Prompt Engineering
Explore how AI prompts can be weaponized for phishing, fake news, harassment, and social engineering. A must-read for hackers, researchers & security pros! ππ€
π‘ Inside the PDF:
β Phishing & Spear Phishing
β Fake News Generation
β Harassment & Social Validation
β Prompt Exploitation & Style Transfer
β‘οΈ Want to take your skills to the next level?
Check out our premium guide π API Security & Hacking Mastery β Full Hands-On Labs + Step-by-Step Pentesting Guide (OWASP Top 10 + Pro Tools) π‘π»
Explore how AI prompts can be weaponized for phishing, fake news, harassment, and social engineering. A must-read for hackers, researchers & security pros! ππ€
π‘ Inside the PDF:
β Phishing & Spear Phishing
β Fake News Generation
β Harassment & Social Validation
β Prompt Exploitation & Style Transfer
β‘οΈ Want to take your skills to the next level?
Check out our premium guide π API Security & Hacking Mastery β Full Hands-On Labs + Step-by-Step Pentesting Guide (OWASP Top 10 + Pro Tools) π‘π»
β€8π3
Bug Bounty Playbook.pdf
13.5 MB
π΅οΈββοΈ Bug Bounty Playbook β FREE eBook
Want to learn how top bug bounty hunters operate?
The Bug Bounty Playbook is a complete step-by-step guide that teaches you how to discover and exploit vulnerabilities in real systems.
π Inside youβll find:
Proven strategies for reconnaissance & enumeration
Practical techniques for spotting XSS, SQLi, CSRF, IDOR and other critical flaws
Detailed real-world exploitation examples with explanations
Workflow tips, methodology, and reporting best practices
This isnβt just theory β itβs a hands-on resource to level up your bug bounty skills and think like a professional hacker.
Want to learn how top bug bounty hunters operate?
The Bug Bounty Playbook is a complete step-by-step guide that teaches you how to discover and exploit vulnerabilities in real systems.
π Inside youβll find:
Proven strategies for reconnaissance & enumeration
Practical techniques for spotting XSS, SQLi, CSRF, IDOR and other critical flaws
Detailed real-world exploitation examples with explanations
Workflow tips, methodology, and reporting best practices
This isnβt just theory β itβs a hands-on resource to level up your bug bounty skills and think like a professional hacker.
β€7
π§Ώ Vulnerability Scanning with Nessus - hexsec.pdf
3.2 MB
π Vulnerability Scanning with Nessus
Nessus is one of the most widely used vulnerability scanning tools in cybersecurity. It allows professionals to identify security weaknesses in systems, networks, and applications before attackers exploit them.
With Nessus, you can:
- Perform automated scans across multiple assets
- Detect misconfigurations, missing patches, and vulnerabilities
- Generate detailed reports for remediation
- Strengthen your security posture with proactive assessments
This guide introduces the basics of Nessus, its setup, and how to run effective scans in a real-world environment.
Nessus is one of the most widely used vulnerability scanning tools in cybersecurity. It allows professionals to identify security weaknesses in systems, networks, and applications before attackers exploit them.
With Nessus, you can:
- Perform automated scans across multiple assets
- Detect misconfigurations, missing patches, and vulnerabilities
- Generate detailed reports for remediation
- Strengthen your security posture with proactive assessments
This guide introduces the basics of Nessus, its setup, and how to run effective scans in a real-world environment.
β€13π₯3
Black_Hat_Python_β_A_Must_Read_for_Ethical_Hackers_&_Pentesters_.pdf
6.9 MB
π Black Hat Python book β A Must-Read for Ethical Hackers & Pentesters
π Python stands out as the #1 hacking language with libraries like Scapy & OpenCV.
πΈ Learn TCP/UDP clients, proxies, and netcat replacements.
π Sniffing & packet analysis: ARP poisoning, credential harvesting, PCAP parsing.
π Web hacking with urllib2, brute forcing, fuzzers & Burp Suite extensions.
π» Trojan development using GitHub as command & control.
β¨οΈ Keyloggers, screenshots & sandbox detection on Windows.
π΅οΈββοΈ Man-in-the-browser attacks via IE COM automation.
π Privilege escalation with WMI, process monitoring & code injection.
π§ Memory analysis & shellcode injection in Virtual Machines with Volatility.
This book is not just theory β itβs a hands-on guide that pushes you to experiment, extend tools, and sharpen your skills in penetration testing and offensive security.
π Python stands out as the #1 hacking language with libraries like Scapy & OpenCV.
πΈ Learn TCP/UDP clients, proxies, and netcat replacements.
π Sniffing & packet analysis: ARP poisoning, credential harvesting, PCAP parsing.
π Web hacking with urllib2, brute forcing, fuzzers & Burp Suite extensions.
π» Trojan development using GitHub as command & control.
β¨οΈ Keyloggers, screenshots & sandbox detection on Windows.
π΅οΈββοΈ Man-in-the-browser attacks via IE COM automation.
π Privilege escalation with WMI, process monitoring & code injection.
π§ Memory analysis & shellcode injection in Virtual Machines with Volatility.
This book is not just theory β itβs a hands-on guide that pushes you to experiment, extend tools, and sharpen your skills in penetration testing and offensive security.
β€12π8π₯2π1
Basic Windows CMD for Pentesters.pdf
3.5 MB
π Basic Windows CMD for Pentesters
A complete cheat sheet with essential and advanced CMD commands every pentester should know. It covers:
β System & environment info
β Processes & services enumeration
β Domain & users reconnaissance
β Network & firewall commands
β WiFi, downloads & misc tricks
π Format: PDF
π Author: HexSec
π‘ A handy guide collecting the most useful CMD commands for quick access during penetration testing.
A complete cheat sheet with essential and advanced CMD commands every pentester should know. It covers:
β System & environment info
β Processes & services enumeration
β Domain & users reconnaissance
β Network & firewall commands
β WiFi, downloads & misc tricks
π Format: PDF
π Author: HexSec
π‘ A handy guide collecting the most useful CMD commands for quick access during penetration testing.
β€10π3π₯°3
Reverse Shells - Windows - HexSecCheatSheet.pdf
3.9 MB
Reverse Shells (Windows) β Defensive Cheat Sheet π‘π‘
What it is:
A concise, lab-ready Windows reverse-shell reference designed for defenders, students, and ethical testers. Use it to recognize common techniques, validate detections, and practice response safely in a controlled environment.
Whatβs inside:
π Quick mapping of popular tools (Netcat/Ncat, sbd, OpenSSL, PowerShell)
π§© Windows LOLBins often abused (mshta, rundll32, regsvr32, certutil, wmic, msbuild)
π§ͺ Frameworks & scripts defenders should know (Nishang, Powercat, Empire, Unicorn)
π§ Blue-team notes: process/network artifacts to watch, on-disk vs in-memory behavior
Why it matters:
Reverse shells show up across real incidents and CTFs. Knowing the tooling and the tell-tale signs helps you tune EDR rules, write detections, and respond faster β before attackers pivot.
What it is:
A concise, lab-ready Windows reverse-shell reference designed for defenders, students, and ethical testers. Use it to recognize common techniques, validate detections, and practice response safely in a controlled environment.
Whatβs inside:
π Quick mapping of popular tools (Netcat/Ncat, sbd, OpenSSL, PowerShell)
π§© Windows LOLBins often abused (mshta, rundll32, regsvr32, certutil, wmic, msbuild)
π§ͺ Frameworks & scripts defenders should know (Nishang, Powercat, Empire, Unicorn)
π§ Blue-team notes: process/network artifacts to watch, on-disk vs in-memory behavior
Why it matters:
Reverse shells show up across real incidents and CTFs. Knowing the tooling and the tell-tale signs helps you tune EDR rules, write detections, and respond faster β before attackers pivot.
β€9π₯6
π¨ Security Alert β CVE-2025-8088 (WinRAR Directory Traversal RCE)
π Date: September 2, 2025
π Severity: Critical
β οΈ Affected: WinRAR versions earlier than 7.13
π Whatβs happening?
A new vulnerability (CVE-2025-8088) in WinRAR allows specially crafted .rar archives to bypass extraction path validation and write files into sensitive system directoriesβsuch as the Windows Startup folderβenabling Remote Code Execution (RCE).
π΅οΈ How does it work?
The flaw lies in WinRARβs ExtractFile() function, which fails to block traversal sequences (../).
Attackers can inject payloads into the Startup directory.
On reboot, the payload auto-executes β persistence + RCE.
π Exploit Github:
https://github.com/hexsecteam/CVE-2025-8088-Winrar-Tool/
π A GUI exploit builder with advanced features (ADS hiding, RAR5 header patching, decoy files, startup targeting).
β οΈ Disclaimer: For educational & authorized use only, not for malicious deployment.
π‘ How to protect yourself
β Update immediately to WinRAR 7.13 o
π Date: September 2, 2025
π Severity: Critical
β οΈ Affected: WinRAR versions earlier than 7.13
π Whatβs happening?
A new vulnerability (CVE-2025-8088) in WinRAR allows specially crafted .rar archives to bypass extraction path validation and write files into sensitive system directoriesβsuch as the Windows Startup folderβenabling Remote Code Execution (RCE).
π΅οΈ How does it work?
The flaw lies in WinRARβs ExtractFile() function, which fails to block traversal sequences (../).
Attackers can inject payloads into the Startup directory.
On reboot, the payload auto-executes β persistence + RCE.
π Exploit Github:
https://github.com/hexsecteam/CVE-2025-8088-Winrar-Tool/
π A GUI exploit builder with advanced features (ADS hiding, RAR5 header patching, decoy files, startup targeting).
β οΈ Disclaimer: For educational & authorized use only, not for malicious deployment.
π‘ How to protect yourself
β Update immediately to WinRAR 7.13 o
GitHub
GitHub - hexsecteam/CVE-2025-8088-Winrar-Tool: A sophisticated GUI tool for creating malicious RAR archives that exploit the WinRARβ¦
A sophisticated GUI tool for creating malicious RAR archives that exploit the WinRAR path traversal vulnerability (CVE-2025-8088) using ADS and RAR5 header manipulation. - hexsecteam/CVE-2025-8088-...
β€21
+100 Linux Command.pdf
587.7 KB
π Want to move faster in the terminal? +100 Linux Commands brings together the essential commands for files/directories, processes, networking & permissions, plus grep/sed/awk, archiving, system info, package management, Git, cron, and handy shell-scripting snippets β ideal for beginners and power users.
π₯10β€5
Kali_Linux_REVELEALED.pdf
11.7 MB
The definitive manual for ethical hackers: βKali Linux Revealed β Mastering the Penetration Testing Distribution (2021).β From clean installs and APT to hardening, custom live ISOs, enterprise rollouts, and a grounded security-assessment methodologyβby the Kali/OffSec team.
β€13π1
Blue Team Toolkit.pdf
14.9 MB
π΅ Blue Team Toolkit β Essential Resources for Defenders π
The Blue Team Toolkit is a complete collection of tools and resources every cybersecurity defender needs. From network discovery and vulnerability management to incident response and malware analysis, this guide has you covered. π
Inside you will find:
πΈ Network Discovery & Mapping: Nmap, Masscan, Shodan, ZMap
π‘ Vulnerability Management: OpenVAS, Nessus, Nexpose
π‘ Security Monitoring: Sysmon, Wazuh, ELK, Splunk
π§© Threat Intelligence: MISP, VirusTotal, MITRE ATT&CK
β‘οΈ Incident Response: NIST 800-61, TheHive, Velociraptor
𧬠Malware Analysis: Cuckoo Sandbox, Ghidra, YARA, ClamAV
πΎ Data Recovery & Forensics: Autopsy, FTK, TestDisk, Volatility
This toolkit empowers defenders to detect, analyze, and respond to cyber threats effectively, making it a must-have for anyone in cybersecurity. π‘
The Blue Team Toolkit is a complete collection of tools and resources every cybersecurity defender needs. From network discovery and vulnerability management to incident response and malware analysis, this guide has you covered. π
Inside you will find:
πΈ Network Discovery & Mapping: Nmap, Masscan, Shodan, ZMap
π‘ Vulnerability Management: OpenVAS, Nessus, Nexpose
π‘ Security Monitoring: Sysmon, Wazuh, ELK, Splunk
π§© Threat Intelligence: MISP, VirusTotal, MITRE ATT&CK
β‘οΈ Incident Response: NIST 800-61, TheHive, Velociraptor
𧬠Malware Analysis: Cuckoo Sandbox, Ghidra, YARA, ClamAV
πΎ Data Recovery & Forensics: Autopsy, FTK, TestDisk, Volatility
This toolkit empowers defenders to detect, analyze, and respond to cyber threats effectively, making it a must-have for anyone in cybersecurity. π‘
β€17π5