
Awesome-BEC
Repository of attack and defensive information for Business Email Compromise investigations

Repository of attack and defensive information for Business Email Compromise investigations



Scans Discord links across mutual guilds to extract profiles, cross‑references 700+ sites, searches usernames with 30+ tools, and generates an…


A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

CVE-2025-9728: Reflected XSS in Login Form (Email & Password Fields) Vvveb CMS v1.0.7.2

Postfix SMTP Smuggling - Expect Script POC

This repository contains an exploit for targeting Microsoft Outlook through Exchange Online, leveraging a vulnerability to execute arbitrary code via…

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

Cross Site Scripting (XSS)

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…

The project was created to demonstrate the use of various tools for capturing NTLM hashes from users on a network and for executing phishing attacks…

🔍 Just wrapped up an incident report on a Phishing Alert (Event ID 257, SOC282). Enhancing my expertise in email threat detection and response! 🚨…

Phishing Simulation mainly aims to increase phishing awareness by providing an intuitive tutorial and customized assessment

Querytool is an OSINT framework based on Google Spreadsheet. With this tool you can perform complex search of terms, people, email addresses, files…