
ExchangeRelayX
An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

Sublime rules for email attack detection, prevention, and threat hunting.

Educational guide on CVE-2024-21413, the Outlook zero-click Moniker Link vulnerability, covering attack flow, NTLM credential capture, detection with…

Repository of attack and defensive information for Business Email Compromise investigations

Spam filtering and email processing framework with regex rules, statistical analysis, custom Lua plugins, and external blocklists for MTA integration.

ThePhish: an automated phishing email analysis tool

Orbis is an full spectrum automated external attack surface intelligent toolkit.

ntlm relay attack to Exchange Web Services

Open-source email filtering framework that detects spam and phishing using content analysis, header checks, Bayesian scoring, and DNS blocklists.

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

A Pythonic interface and command line tool for interacting with the InQuest Labs API.

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

Proof-of-concept exploit for Microsoft Outlook RCE (CVE-2024-21413) with SMTP-based phishing email delivery, malicious RTF attachment generation, and…

Exim Honey Pot for CVE-2019-10149 exploit attempts.

Documentation of CVE-2024-50964: critical DMARC policy bypass in DonWeb MX server allowing email spoofing, with low attack complexity and no required…

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

Educational lab and PoC demonstrating CVE-2024-21413 Outlook Moniker Link attack to leak netNTLMv2 hashes via crafted HTML email.

A toolkit to attack Office365