#1Tools for creating, managing, and analyzing fake login pages and email campaigns.
Kitploit recommended

In LetterPress plugin <= 1.2.1 is vulnerable to Html Injection Vulnerability which can futher leads to Open Redirection Vulnerabilty.

USBCoercer turns an ESP32 development board with native USB-OTG into an Ethernet-over-USB gadget capable of coercing proxy configuration via WPAD.

Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens


Self contained htaccess shells and attacks

CVE-2026-13156 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).

CVE Reproduction: cve-2024-43451-ntlm_hash_disclosure_reproduction

CVE-2026-XXXX: Atlassian GraphQL Email Enumeration Oracle (CWE-204, CVSS 5.3 MEDIUM)

Educational PDF files demonstrating client-side exploitation techniques, including calculator execution and directory browsing, for security testing…

An automated Wireless RogueAP MITM attack framework.

Windows Remote Post Breach Tool via Telegram

A Windows Remote Administration Tool in Visual Basic with UNC paths

Successor of Undetected-Chromedriver. Providing a blazing fast framework for web automation, webscraping, bots and any other creative ideas which are…

Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻