
zeek
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

Open-source interactive security awareness training library with 130+ SCORM exercises covering phishing, vishing, BEC, MFA fatigue, and OWASP AI/LLM…

Open-source email filtering framework that detects spam and phishing using content analysis, header checks, Bayesian scoring, and DNS blocklists.

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Deploy a phishing infrastructure on the fly.

A toolkit to attack Office365

Exploit for Outlook 2019 zero-click vulnerability CVE-2020-1349, using MIME header parsing bugs to achieve heap overflow and EIP control via vftable…


Artifacts for the USENIX publication.

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

Documentation of my hands-on lab Moniker Link (CVE-2024-21413) completed on TryHackMe.

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

Documentation of CVE-2026-31283: an email bombing vulnerability in Totara LMS's forgot password API due to missing rate limiting, allowing…

A simple Reverse Shell that can communicate through Gmail SMTP or any other SMTP to evade network restrictions

Automation to assess the state of your M365 tenant against CISA's baselines

Detection method for Exim vulnerability CVE-2024-39929

A tool to abuse Exchange services