
falco
Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

A Pythonic interface and command line tool for interacting with the InQuest Labs API.

Browser-based OSINT mapper for cyber crime: enriches IPs, domains, and emails via Shodan, Hudson Rock, and IPInfo; analyzes email headers/time deltas…

Research tool that tests Outlook for HTML email leakage, allowing SMB hash hijacking and user tracking via crafted email payloads.

Identify public-facing Microsoft Exchange servers and determine their software versions

Rust-based pattern matching engine for malware researchers. Create YARA rules with textual/binary patterns, wildcards, and regex to identify and…

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

Educational lab demonstrating CVE-2024-21413 Outlook vulnerability exploitation with Python email exploit tool and Responder for NTLM credential…

Python tool to exploit CVE-2021-26855 (ProxyLogon) for downloading Exchange mailbox emails via EWS, supporting user enumeration and bulk target…

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

Comprehensive DNS reconnaissance and OSINT toolkit for domain intelligence gathering. Queries all major record types, performs email security…

This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known…

Streaming MBOX viewer and email forensics tool for browsing, searching, and exporting large mail archives (50GB+) from Gmail Takeout or any MBOX…

Abuse Exchange services via MAPI/HTTP or RPC/HTTP to enumerate users, create malicious mail rules, execute VBScript through Outlook forms/homepage,…

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

HOCig- Automatic HOC Information Gathering Tool V 1.2

Parses email headers to extract hop delays, source IPs, and country origins, converting raw MIME data into human-readable forensic analysis for…