
SECMON
SECMON is a web-based tool for the automation of infosec watching and vulnerability management with a web interface.

:mailbox: Cross-language temporary (disposable/throwaway) email detection library. Covers 55 734+ fake email providers.

ThePhish: an automated phishing email analysis tool

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

Educational lab and PoC demonstrating CVE-2024-21413 Outlook Moniker Link attack to leak netNTLMv2 hashes via crafted HTML email.

E-Mail Header Analyzer

Improved SMTP Checker / SMTP Cracker with proxy-support, inbox test and many more features.

HOCig- Automatic HOC Information Gathering Tool V 1.2

Identify public-facing Microsoft Exchange servers and determine their software versions

This tool helps identify exposure to CVE-2025-20393 by checking for open TCP/6025 ports, responsive Spam Quarantine interfaces, and known…

A program to map out SPF and DKIM records for a large number of domains

Mail-in-a-Box helps individuals take back control of their email by defining a one-click, easy-to-deploy SMTP+everything else server: a mail server…

🦄 A curated list of privacy & security-focused software and services

Automation to assess the state of your M365 tenant against CISA's baselines


FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule…

Repository of attack and defensive information for Business Email Compromise investigations

Bash script to check if a domain or list of domains can be spoofed based in DMARC records