Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Awesome-BEC — Repository of attack and defensive information for Business Email Compromise investigations | Kitploit
Tools/GitHubGitHub/randomaccess3/awesome-bec
Phishing ToolsDigital ForensicsCloud SecurityThreat IntelligenceIdentity & Access Management (IAM)Learning & EducationRed TeamingIncident ResponseCurated ResourcesEmail Security
GitHubrandomaccess3/awesome-bec
27833243 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Awesome-BEC

Repository of attack and defensive information for Business Email Compromise investigations

View Repository

Awesome-BEC

Repository of attack and defensive information for Business Email Compromise investigations

Office365/AzureAD

  • ATT&CK O365
  • ATT&CK Azure
  • Microsoft Azure Threat Research Matrix
  • Microsoft 365 Licensing
  • Microsoft Portals
  • Azure App IDs
  • Microsoft First Party App IDs & Graph Permissions
  • Well-known Microsoft Client IDs

Attack/Defend Research

AuthorLink
Lina LauBackdoor Office 365 and Active Directory - Golden SAML
Lina LauOffice365 Attacks: Bypassing MFA, Achieving Persistence and More - Part I
Lina LauAttacks on Azure AD and M365: Pawning the cloud, PTA Skeleton Keys and more - PART II
Mike Felch and Steve BoroshSocially Acceptable Methods to Walk in the Front Door
MandiantRemediation and Hardening Strategies for Microsoft 365 to Defend Against UNC2452
Andy Robbins at SpecterOpsAzure Privilege Escalation via Service Principal Abuse
Emilian Cebuc & Christian Philipov at F-SecureHas anyone seen the principal?
nyxgeek at TrustedSecCreating A Malicious Azure AD Oauth2 Application
Lina LauHow to Backdoor Azure Applications and Abuse Service Principals
Lina LauHow to Detect Azure Active Directory Backdoors: Identity Federation
Doug Bienstock at MandiantPwnAuth
Steve Borosh at Black Hills Information SecucirtySpoofing Microsoft 365 Like It’s 1995
AvertiumMITM Attacks - Evilproxy and Evilginx
Aon Cyber LabsBypassing MFA: A Forensic Look At Evilginx2 Phishing Kit
Sofia MarinIncident Response Series: Chapter #1 Phishing and cookie stolen with Evilginx.
Sofia MarinIncident Response Series: Chapter #3 The Impact and Subscription Theft as Exfiltration
Anish BogatiTricked by trust: How OAuth and device code flows get abused

Investigation Research

Download Tool