
area51
The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Repository of attack and defensive information for Business Email Compromise investigations

Python script to detect CVE-2023-3128 authentication bypass in Grafana via Azure AD email claim validation. Checks Azure AD SSO configuration and…

Modular Java mail server supporting IMAP, SMTP, POP3, and JMAP with Docker deployment, distributed architecture, and CLI management for secure…

PowerShell-based detection and remediation toolkit for CVE-2025-32711 (EchoLeak), a critical zero-click AI command injection vulnerability in…

290+ Automated checks across 14 compliance frameworks, interactive HTML report, no data leaves your machine.

Open source tooling to stop ICS phishing (malicious calendar invites)

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

Automated network asset, email, and social media profile discovery and cataloguing.

Azure JWT Token Manipulation Toolset

Orbis is an full spectrum automated external attack surface intelligent toolkit.

User enumeration and password bruteforce on Azure, ADFS, OWA, O365, Teams and gather emails on Linkedin

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

Enumerate Microsoft 365 Groups in a tenant with their metadata