Skip to content
@qeeqbox

QeeqBox

State-of-the-art opensource projects and services for red, purple, and blue teams

Pinned Loading

  1. social-analyzer social-analyzer Public

    API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites

    JavaScript 24k 2.3k

  2. analyzer analyzer Public

    Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries, emails and more)

    Python 322 67

  3. chameleon chameleon Public

    19 Customizable honeypots for monitoring network traffic, bots activities and username\password credentials (DNS, HTTP Proxy, HTTP, HTTPS, SSH, POP3, IMAP, STMP, RDP, VNC, SMB, SOCKS5, Redis, TELNE…

    Dockerfile 840 125

  4. url-sandbox url-sandbox Public

    Scalable URL Sandbox for analyzing URLs and Domains from phishing attacks

    Python 204 59

  5. raven raven Public

    Advanced Cyber Threat Map (Simplified, customizable, responsive and optimized)

    JavaScript 234 56

  6. honeypots honeypots Public

    30 different honeypots in one package! (dhcp, dns, elastic, ftp, http proxy, https proxy, http, https, imap, ipp, irc, ldap, memcache, mssql, mysql, ntp, oracle, pjl, pop3, postgres, rdp, redis, si…

    Python 988 139

Repositories

Showing 10 of 94 repositories
  • vulnerable-web-app Public

    vulnerable-web-app

    qeeqbox/vulnerable-web-app's past year of commit activity
    Python 3 AGPL-3.0 1 0 0 Updated Aug 26, 2026
  • xxe-injection Public

    A threat actor may interfere with an application's processing of extensible markup language (XML) data to view the content of a target's files

    qeeqbox/xxe-injection's past year of commit activity
    2 AGPL-3.0 0 0 0 Updated Aug 26, 2026
  • xslt-injection Public

    A threat actor may interfere with an application's processing of extensible stylesheet language transformations (XSLT) for extensible markup language (XML) to read or modify data on the target

    qeeqbox/xslt-injection's past year of commit activity
    2 AGPL-3.0 0 0 0 Updated Aug 16, 2026
  • xml-injection Public

    A threat actor may exploit XML processing in an application to read, alter, or disrupt data.

    qeeqbox/xml-injection's past year of commit activity
    1 AGPL-3.0 0 0 0 Updated Aug 16, 2026
  • os-command-injection Public

    A threat actor may inject arbitrary operating system (OS) commands on target

    qeeqbox/os-command-injection's past year of commit activity
    1 AGPL-3.0 0 0 0 Updated Aug 4, 2026
  • open-redirect Public

    A threat actor may send a malicious redirect request for a vulnerable target to a victim; the victim gets redirected to a malicious website that threat actor controls

    qeeqbox/open-redirect's past year of commit activity
    2 AGPL-3.0 1 0 0 Updated Aug 4, 2026
  • dom-based-cross-site-scripting Public

    A threat actor may inject malicious content into webapp. The payload is not reflected in the HTTP request and response, then executed in the victim's browser

    qeeqbox/dom-based-cross-site-scripting's past year of commit activity
    4 AGPL-3.0 2 0 0 Updated Aug 3, 2026
  • reflected-cross-site-scripting Public

    A threat actor may inject malicious content into webapp. The payload is reflected in the HTTP request and response, then executed in the victim's browser

    qeeqbox/reflected-cross-site-scripting's past year of commit activity
    6 AGPL-3.0 3 0 0 Updated Aug 4, 2026
  • stored-cross-site-scripting Public

    A threat actor may inject malicious content into a vulnerable target

    qeeqbox/stored-cross-site-scripting's past year of commit activity
    5 AGPL-3.0 3 0 0 Updated Aug 4, 2026
  • session-replay Public

    A threat actor may re-use a stolen or leaked session identifier to access the user's account

    qeeqbox/session-replay's past year of commit activity
    2 AGPL-3.0 0 0 0 Updated Aug 4, 2026