- Home
- Security Operations
- Offensive Security
- Shadow Workers
Shadow Workers
Shadow Workers is an open source C2 framework and proxy tool for penetration testers to exploit XSS vulnerabilities and malicious Service Workers.

Shadow Workers
Shadow Workers is an open source C2 framework and proxy tool for penetration testers to exploit XSS vulnerabilities and malicious Service Workers.
Shadow Workers Description
Shadow Workers is an open source command and control (C2) framework and proxy tool designed for penetration testing activities. The tool focuses on exploiting Cross-Site Scripting (XSS) vulnerabilities and malicious Service Workers to establish command and control channels. It provides an interface for creating and managing C2 servers, enabling penetration testers to test and exploit web application vulnerabilities. The framework supports proxy functionality to facilitate communication between compromised targets and the C2 infrastructure. Shadow Workers is specifically designed to assist security researchers and penetration testers in assessing web application security through Service Worker exploitation techniques.
Shadow Workers FAQ
Common questions about Shadow Workers including features, pricing, alternatives, and user reviews.
Shadow Workers is Shadow Workers is an open source C2 framework and proxy tool for penetration testers to exploit XSS vulnerabilities and malicious Service Workers.. It is a Security Operations solution designed to help security teams with C2, Web Security, Offensive Security.
FEATURED
Password manager with end-to-end encryption and identity protection features
VPN service providing encrypted internet connections and privacy protection
Fractional CISO services for B2B companies to accelerate sales and compliance
Stay Updated with Mandos Brief
Get the latest cybersecurity updates in your inbox
TRENDING CATEGORIES
POPULAR
Security platform that provides protection, monitoring and governance for enterprise generative AI applications and LLMs against various threats including prompt injection and data poisoning.
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
OSINTLeak is a tool for discovering and analyzing leaked sensitive information across various online sources to identify potential security risks.
Weekly cybersecurity newsletter for security leaders and professionals