
Awesome-BEC
Repository of attack and defensive information for Business Email Compromise investigations

Repository of attack and defensive information for Business Email Compromise investigations

Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)

Python exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Sends a crafted email via SMTP to trigger code execution…

Proof of Work of CVE-2023-23397 for vulnerable Microsoft Outlook client application.

This repository contains an exploit for targeting Microsoft Outlook through Exchange Online, leveraging a vulnerability to execute arbitrary code via…

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

Proof-of-concept exploit for CVE-2013-2977: IBM Lotus Notes PNG integer overflow leading to arbitrary code execution when a malicious email is opened…