
M365-Assess
290+ Automated checks across 14 compliance frameworks, interactive HTML report, no data leaves your machine.

290+ Automated checks across 14 compliance frameworks, interactive HTML report, no data leaves your machine.

Test cases for broken MIME and tools to generate and process these

Python PoC for CVE-2026-73570, an SMTP command injection in Zimbra. Sends malformed RCPT TO payloads to trigger shell command execution via…

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Bulk domain spoofability checker using authoritative SPF and DMARC record analysis with custom, real-world tested spoof logic and optional DKIM…

Automated Outlook account registration tool using pure HTTP protocol with PerimeterX captcha solving, proxy pool management, and email token…

A toolkit to attack Office365

Orbis is an full spectrum automated external attack surface intelligent toolkit.

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

Repository of attack and defensive information for Business Email Compromise investigations

True P2P Email on top of Yggdrasil Network for Android

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

Exploit for the CVE-2023-23397

Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

Proof-of-concept exploit for CVE-2020-16947, a Microsoft Outlook RCE triggered by malformed HTML content leading to a heap buffer overflow and remote…

Python3 rewrite of AsOutsider features of AADInternals

Tool to find SMTP servers vulnerable to open relay