
o365-attack-toolkit
A toolkit to attack Office365

A toolkit to attack Office365

CVE-2024-42009 Proof of Concept

Paperweight scans your inbox to map your digital footprint, then helps you take back control and delete your data. Local-first and open source.

mboxShell. Fast terminal viewer for MBOX files of any size. Open, search and export emails from Gmail Takeout backups (50GB+) without loading them…

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

Data leak checker & OSINT Tool

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

PowerShell script to exploit CVE-2023-23397 by sending or saving malicious Outlook calendar invitations that trigger NTLM credential leakage via the…

The Outlook HTML Leak Test Project

These detection scripts are property of the SECPlayground Platform. Two safe detection scripts. Neither drives the close_notify-mid-BDAT trigger, so…

C# tool for red team operations that extracts contacts, mailbox metadata, and searches emails via Outlook COM object, with built-in Programmatic…

Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC

Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)

Proof-of-concept exploit for CVE-2026-11113, demonstrating SMTP header injection in a Flask contact form via unsanitized email input; includes…