
falco
Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

Python email address and Mime parsing library

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Automation to assess the state of your M365 tenant against CISA's baselines

A Pythonic interface and command line tool for interacting with the InQuest Labs API.

Spoof emails from any of the +2 Million domains using MailChannels (DEFCON 31 Talk)

Browser-based OSINT mapper for cyber crime: enriches IPs, domains, and emails via Shodan, Hudson Rock, and IPInfo; analyzes email headers/time deltas…

Research tool that tests Outlook for HTML email leakage, allowing SMB hash hijacking and user tracking via crafted email payloads.

Identify public-facing Microsoft Exchange servers and determine their software versions

Web-based tool for adding shadow users with SHA-512 password hashing and auto-aging detection, featuring multiple write fallback methods for system…

Rust-based pattern matching engine for malware researchers. Create YARA rules with textual/binary patterns, wildcards, and regex to identify and…

Most Powerful Send Fake Mail Using Any Mail I'd undetectable

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

Educational lab demonstrating CVE-2024-21413 Outlook vulnerability exploitation with Python email exploit tool and Responder for NTLM credential…

Python tool to exploit CVE-2021-26855 (ProxyLogon) for downloading Exchange mailbox emails via EWS, supporting user enumeration and bulk target…

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

DNSint - A comprehensive DNS reconnaissance and OSINT toolkit for domain intelligence gathering and security analysis.

This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known…