
ScubaGear
Automation to assess the state of your M365 tenant against CISA's baselines

Automation to assess the state of your M365 tenant against CISA's baselines

Identify public-facing Microsoft Exchange servers and determine their software versions

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.


This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known…

Spam Scanner is a Node.js anti-spam, email filtering, and phishing prevention tool and service. Built for @ladjs, @forwardemail, @cabinjs, @breejs,…

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

A tool to abuse Exchange services

A simple Reverse Shell that can communicate through Gmail SMTP or any other SMTP to evade network restrictions

Spoof emails from any of the +2 Million domains using MailChannels (DEFCON 31 Talk)

small python3 tool to check common vulnerabilities in SMTP servers

An email spoofing testing tool that aims to bypass SPF/DKIM/DMARC and forge DKIM signatures.🍻

A temporary email right from your terminal written in POSIX sh

SECMON is a web-based tool for the automation of infosec watching and vulnerability management with a web interface.

C# tool for red team operations that extracts contacts, mailbox metadata, and searches emails via Outlook COM object, with built-in Programmatic…

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

HOCig- Automatic HOC Information Gathering Tool V 1.2

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…