#1Tools for creating, managing, and analyzing fake login pages and email campaigns.
Kitploit recommended

🐱💻 👍 Google Chrome - File System Access API - vulnerabilities reported by Maciej Pulikowski | Total Bug Bounty Reward: $5.000 | CVE-2021-21123…

All-in-One WP Migration < 7.63 - Unauthenticated Reflected XSS + CSRF

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

Stored XSS via CSRF in Beetel 777VR1 Router

CVE-2020-13965: Cross-Site Scripting via Malicious XML Attachment in Roundcube Webmail

Persistent XSS on Comtrend AR-5387un router

Chamilo-LMS (v2.0) CVE-2025-26153

An XSS exploitation command-line interface and payload generator.

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

Hunt down social media accounts by username across social networks

CVE-2025-8088 exploitation chain + Quasar C2 multi-stage payload delivery

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

Educational Telegram phishing simulation for cybersecurity training and awareness. Demonstrates credential harvesting via fake login pages in…

A Proof-of-Concept using Cache Smuggling + Exif data to passively download a second stage payload

This is a proof-of-work for abusing git's clean filter against IDEs & Sublime.