
Awesome-BEC
Repository of attack and defensive information for Business Email Compromise investigations

Repository of attack and defensive information for Business Email Compromise investigations



Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover





Scans Discord links across mutual guilds to extract profiles, cross‑references 700+ sites, searches usernames with 30+ tools, and generates an…


Template Injection in Email Templates leads to code execution on Jira Service Management Server

A comprehensive, step-by-step guide to mastering cybersecurity from beginner to expert level with curated resources, tools, and career guidance

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).


An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

It’s an OSINT reconnaissance poc powered by Local LLMs (Ollama). You can feed it an email, domain, or IP, and it automatically performs multiple…