
Microsoft365_devicePhish
A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

A high-speed covert tunnel that disguises TCP traffic as SMTP email communication to bypass Deep Packet Inspection (DPI) firewalls.

Zero-Knowledge Credential Sharing

DLL that hooks NTLM and Kerberos authentication in lsass.exe to inject a backdoor hash, enabling persistent authenticated access on Windows systems.

A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.

Fork of laravel/framework 10.50.2 with CVE-2026-48019 (CRLF injection in default email rule) backported into ValidatesAttributes::validateEmail.…

This script helps to pass through the captive portals in public Wi-Fi networks. It hijacks IP and MAC from somebody who is already connected and…

Active Directory reconnaissance and exploitation for Red Teams via the Active Directory Web Services (ADWS).

Advanced phishing tool combining OAuth Device Code authentication flow with QR codes to harvest Microsoft authentication tokens via MFA update…

psexecsvc - a python implementation of PSExec's native service implementation

C# implementation of SMBExec for remote command execution on Windows targets using NTLM password hashes, enabling lateral movement and pass-the-hash…

Simple PoC in PowerShell for CVE-2023-23397

Dump Kerberos tickets from the KCM database of SSSD

An exploitation demo of Outlook Elevation of Privilege Vulnerability