
Tyr
True P2P Email on top of Yggdrasil Network for Android

True P2P Email on top of Yggdrasil Network for Android

Published security research repository featuring academic papers on domain hijacking, 2FA bypass, and large-scale spoofing techniques, authored by…

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

Blue-team lab: detecting & mitigating CVE-2025-24054 (Windows NTLM hash disclosure) with Sysmon, Wazuh SIEM, and Group Policy

Penetration testing lab demonstrating CVE-2024-21413 moniker link exploitation for NTLM credential theft, including attack execution, hash cracking,…

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

Advanced phishing tool combining OAuth Device Code authentication flow with QR codes to harvest Microsoft authentication tokens via MFA update…

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

Social Media Infrastructure Vulnerability Research. CVE-2026-78905: OAuth token reuse and session hijacking in Facebook's Graph API.

Dockerized mail server suite with Postfix, Dovecot, Rspamd, and ClamAV. Provides secure email hosting with integrated spam filtering, antivirus, and…

🦄 A curated list of privacy & security-focused software and services

Modlishka. Reverse Proxy.

SSH-MITM - ssh audits made simple

evilginx3 + gophish

A Python package and CLI for parsing aggregate and forensic DMARC reports