
GraphSpy
Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Remote operations commands implemented using Beacon Object Files

A fork of the great TokenTactics with support for CAE and token endpoint v2

Azure JWT Token Manipulation Toolset


OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

Serverless AITM Simulation Framework for Entra ID and M365

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

Self-hosted email alias masking service using Postfix and Telegram bot to create disposable addresses for signups, with full control over email…

Collection of tools to use with Azure Applications

Kali365 - EvilTokens Replica

tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

PowerShell proof-of-concept for CVE-2023-23397 that exploits Outlook's ReminderSoundFile property to intercept Net-NTLMv2 hashes via SMB or WebDAV…

Facebook brute forcer script

Proof-of-concept exploit demonstrating OTP bypass in One Identity Cloud Access Manager 8.1.3 via MITM/SSL-strip, SAML response replay, and injected…