Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2023-23397-purple-team — Purple team project exploiting CVE-2023-23397 Outlook NTLM leak with phishing delivery, plus Sigma/Wazuh detections mapped to MITRE ATT&CK for the attack chain. | Kitploit
Tools/GitHubGitHub/praneethnaidu1910-cmd/cve-2023-23397-purple-team
ExploitationPhishingLearning & EducationRed TeamingEmail SecurityLabs & Practice
GitHubpraneethnaidu1910-cmd/cve-2023-23397-purple-team

cve-2023-23397-purple-team

Purple team project exploiting CVE-2023-23397 Outlook NTLM leak with phishing delivery, plus Sigma/Wazuh detections mapped to MITRE ATT&CK for the attack chain.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
13h 45m agoNot yet reviewed
Share

CVE-2023-23397 — Purple Team: Exploit + Detection

Two halves of one project against the same Outlook NTLM-leak vulnerability (CVE-2023-23397):

  • Red team (done): phishing delivery + exploitation of CVE-2023-23397 against a Windows 10 victim VM, full writeup in FINAL_PROJECT_REPORT.pdf, walkthrough in FINAL_DEMO_VIDEO.mp4, slides in Presentation.pptx. Delivery scripts (send_malicious_email.py, malicious_email_url.py) and the phishing lure page (index.html) are included for reference.
  • Blue team (in progress): detection-engineering-lab/ — Sigma/Wazuh detections for every stage of that same attack chain, mapped to MITRE ATT&CK, each with a measured false-positive rate against a benign baseline, plus a small automation layer that summarizes daily alerts.

Build log and task-by-task plan for the detection lab: Detection_Engineering_Project_Plan.md.

All of this ran against VMs I control (Windows 10 victim, Kali attacker) in an isolated lab — not against any real target.

Download Tool