
ScubaGear
Automation to assess the state of your M365 tenant against CISA's baselines

Automation to assess the state of your M365 tenant against CISA's baselines

Spoof emails from any of the +2 Million domains using MailChannels (DEFCON 31 Talk)

Identify public-facing Microsoft Exchange servers and determine their software versions

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.


Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known…

A tool to abuse Exchange services

ntlm relay attack to Exchange Web Services

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

small python3 tool to check common vulnerabilities in SMTP servers

HOCig- Automatic HOC Information Gathering Tool V 1.2

Tool to find SMTP servers vulnerable to open relay

E-Mail Header Analyzer

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

C# tool for red team operations that extracts contacts, mailbox metadata, and searches emails via Outlook COM object, with built-in Programmatic…

A temporary email right from your terminal written in POSIX sh

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…