
area51
The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Proof-of-concept exploit for an actively exploited Zimbra Collaboration Suite vulnerability, designed for authorized penetration testing and…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule…

A script that helps you understand why your E-Mail ended up in Spam

Paperweight scans your inbox to map your digital footprint, then helps you take back control and delete your data. Local-first and open source.

Web application that lets you test if your domain is vulnerable to email spoofing

Scrape Pastebin API to collect daily pastes, setup a wordlist and be alerted by email when you have a match.


Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

A tool to abuse Exchange services

Disposable email inbox powered by serverless mailgun kittens

Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

Most Powerful Send Fake Mail Using Any Mail I'd undetectable

Automated SPF and DMARC configuration checker that identifies email spoofing vulnerabilities across single or bulk domains using DNS lookups.

HOCig- Automatic HOC Information Gathering Tool V 1.2

Proof-of-concept exploit for Microsoft Outlook RCE (CVE-2024-21413) with SMTP email delivery, malicious RTF attachment generation, and optional…

Proof-of-concept exploit for Microsoft Outlook RCE (CVE-2024-21413) with SMTP-based phishing email delivery, malicious RTF attachment generation, and…