awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
ultrasecurity avatar

ultrasecurity/Storm-Breaker

0
View on GitHub↗
4,808 stars·1,737 forks·HTML·13 viewsultraamooz.com↗

Storm Breaker

Storm-Breaker is a browser-based surveillance toolkit designed to silently capture sensor data from visitors without their knowledge or consent. It combines device fingerprinting, network-based geolocation tracking, and WebRTC exploitation to access a remote device’s camera, microphone, and system information without triggering native permission prompts.

The toolkit achieves this by leveraging legacy browser APIs and network-based geolocation (IP, Wi-Fi) that do not require explicit user permission. It abuses WebRTC and media stream APIs to activate camera and microphone streams, while also collecting hardware and software details through stealth fingerprinting. All captured data is exfiltrated to a remote server via HTTP or WebSocket connections, orchestrated from a single-page web interface.

Storm-Breaker provides capabilities for webcam feed capture, microphone audio recording, device location tracking, and hardware/software reconnaissance, all operating outside standard consent workflows. The project is presented as a self-contained tool for exploring these browser API exploitations.

Features

  • Surveillance Toolkits - A browser-based surveillance toolkit that captures webcam, microphone, and device information without consent.
  • Client-Side Exfiltration Channels - Transmits captured sensor data to a remote server via HTTP or WebSocket connections.
  • Permissionless - Determines a device's approximate geographical location using IP and Wi-Fi signals for surveillance.
  • Permissionless Geolocation Trackers - Estimates a device's location using IP addresses and network signals without explicit permission.
  • Permissionless Network Geolocation - Uses network-based geolocation (IP, Wi-Fi) to determine approximate location without permission.
  • Permissionless Microphone Access - Records audio from a remote device's microphone using browser APIs without permission prompts.
  • Permissionless Microphone Recording - Records audio from a device's microphone without alerting the user or requesting permission.
  • Permissionless Webcam Streaming - Activates and streams a remote device's camera through a browser without the user's knowledge.
  • Permissionless Webcam Capture - Activates the camera on a remote device and captures live video for streaming or recording.
  • Network-Based Location Tracking - Tracks a device's geographic location using network-based methods without user notification.
  • WebRTC Media Hijacking - Abuses WebRTC and media stream APIs to activate camera and microphone without permission dialogs.
  • Sensor Hijacking Scripts - Uses unsecured JavaScript APIs to capture camera, microphone, and location data from visitors.
  • Device Fingerprinting - Gathers detailed device information like OS, browser version, and hardware specs without user consent.
  • Stealth Fingerprinting Techniques - Captures hardware and software details through browser fingerprinting without alerting the user.
  • Permissionless API Exploits - Leverages browser APIs that do not require user permission to harvest data silently.
  • WebRTC Exploitation Tools - Abuses WebRTC and getUserMedia to access camera and microphone streams silently.
  • Permission Bypass Exploits - Exploits browser API quirks to access sensors without triggering native permission prompts.
  • Device Information Harvesting - Harvests device-specific details such as operating system, browser version, and hardware specs.
  • Surveillance Dashboards - Provides a self-contained web application that orchestrates multi-sensor data capture and exfiltration.

Star history

Star history chart for ultrasecurity/storm-breakerStar history chart for ultrasecurity/storm-breaker

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Storm Breaker

These projects share indexed features with Storm Breaker. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • lucksi/mr.holmesLucksi avatar

    Lucksi/Mr.Holmes

    3,032View on GitHub↗

    Mr.Holmes is an open-source intelligence investigation framework designed to gather public data from phone numbers, usernames, IP addresses, and domains. It functions as a collection of tools for digital footprint analysis and social media reconnaissance. The system integrates several specialized capabilities, including a search engine dorking tool for uncovering hidden public records and a geolocation utility for identifying the physical location and ownership of network addresses. It also includes a social media reconnaissance system that scrapes and links public profiles using usernames an

    Pythongeolocationinformation-gatheringkali-linux
    View on GitHub↗3,032
  • ntop/ntopngntop avatar

    ntop/ntopng

    7,880View on GitHub↗

    ntopng is a web-based network traffic monitoring tool and flow data aggregator. It functions as a network security monitor, an SNMP network management system, and an industrial protocol analyzer for OT and SCADA environments. The system provides specialized inspection for industrial protocols such as Modbus, DNP3, and IEC 60870. It distinguishes itself through behavioral threat detection, encrypted traffic analysis via handshake fingerprinting, and the ability to identify hardware and operating systems using DHCP and MAC address patterns. Its broader capabilities include real-time traffic an

    Lua
    View on GitHub↗7,880
  • cellularprivacy/android-imsi-catcher-detectorCellularPrivacy avatar

    CellularPrivacy/Android-IMSI-Catcher-Detector

    5,335View on GitHub↗

    This project is a mobile network security auditor and IMSI catcher detector designed to identify fake base stations and surveillance hardware attempting to intercept mobile traffic. It functions as a radio interface analyzer and cellular tower mapping tool, monitoring connections to detect unauthorized network infrastructure. The system distinguishes itself by combining real-time threat level monitoring with the ability to identify silent SMS and stealth communications used for device tracking. It analyzes ciphering status to detect forced network downgrades to weaker encryption standards and

    Java
    View on GitHub↗5,335
  • samyk/evercookiesamyk avatar

    samyk/evercookie

    4,723View on GitHub↗

    Evercookie is a JavaScript tracking script designed for persistent user identification. It implements a system that mirrors unique identifiers across multiple browser storage mechanisms to maintain tracking after a user clears their browser history. The tool ensures data persistence by synchronizing identifiers across cookies, local storage, and legacy plugin caches. It uses automatic storage regeneration to refill empty storage slots from surviving sources and employs a majority-vote selection process to determine the correct identifier when retrieving data. The project also includes capabi

    JavaScript
    View on GitHub↗4,723
Compare all 13 related projects→

Frequently asked questions

What does ultrasecurity/storm-breaker do?

Storm-Breaker is a browser-based surveillance toolkit designed to silently capture sensor data from visitors without their knowledge or consent. It combines device fingerprinting, network-based geolocation tracking, and WebRTC exploitation to access a remote device’s camera, microphone, and system information without triggering native permission prompts.

What are the main features of ultrasecurity/storm-breaker?

The main features of ultrasecurity/storm-breaker are: Surveillance Toolkits, Client-Side Exfiltration Channels, Permissionless, Permissionless Geolocation Trackers, Permissionless Network Geolocation, Permissionless Microphone Access, Permissionless Microphone Recording, Permissionless Webcam Streaming.

Which projects share features with ultrasecurity/storm-breaker?

Projects with overlapping indexed features include: techchipnet/camphish — CamPhish is a social engineering framework and phishing tool designed to capture webcam photos and GPS coordinates… samyk/evercookie — Evercookie is a JavaScript tracking script designed for persistent user identification. It implements a system that… cellularprivacy/android-imsi-catcher-detector — This project is a mobile network security auditor and IMSI catcher detector designed to identify fake base stations… ntop/ntopng — ntopng is a web-based network traffic monitoring tool and flow data aggregator. It functions as a network security… lucksi/mr.holmes — Mr.Holmes is an open-source intelligence investigation framework designed to gather public data from phone numbers,… thewhiteh4t/seeker — Seeker is a social engineering location tool and browser geolocation capture system. It provides a framework for…