
CVE-2026-24031
Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Microsoft Entra ID (Azure AD) Unauthenticated Enumeration

Most Powerful Send Fake Mail Using Any Mail I'd undetectable

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

OsintNET is a browser-based OSINT platform for domain intelligence, website risk scanning, SERP discovery, image intelligence and AI image detection.

just idea, no cp pls

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

ThePhish: an automated phishing email analysis tool

Enumerate valid users on Office 365 and Exchange via time-based and error-based techniques across multiple exposed services, including OWA,…

Bash script to check if a domain or list of domains can be spoofed based in DMARC records

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…