
ScubaGear
Automation to assess the state of your M365 tenant against CISA's baselines

Automation to assess the state of your M365 tenant against CISA's baselines

290+ Automated checks across 14 compliance frameworks, interactive HTML report, no data leaves your machine.

Orbis is an full spectrum automated external attack surface intelligent toolkit.

Mail-in-a-Box helps individuals take back control of their email by defining a one-click, easy-to-deploy SMTP+everything else server: a mail server…

Identify public-facing Microsoft Exchange servers and determine their software versions

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

A toolkit to attack Office365

Repository of attack and defensive information for Business Email Compromise investigations

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

Open source tooling to stop ICS phishing (malicious calendar invites)

Tuning and refactoring Google Chronicle Curated Detections to eliminate alert fatigue and fix logic gaps/bugs.

PowerShell-based detection and remediation toolkit for CVE-2025-32711 (EchoLeak), a critical zero-click AI command injection vulnerability in…

PowerShell script to detect and remediate CVE-2023-23397 privilege escalation vulnerability in Microsoft Outlook and Exchange environments.

Modular Java mail server supporting IMAP, SMTP, POP3, and JMAP with Docker deployment, distributed architecture, and CLI management for secure…