
ScubaGear
Automation to assess the state of your M365 tenant against CISA's baselines

Automation to assess the state of your M365 tenant against CISA's baselines

290+ Automated checks across 14 compliance frameworks, interactive HTML report, no data leaves your machine.

Orbis is an full spectrum automated external attack surface intelligent toolkit.

🦄 A curated list of privacy & security-focused software and services

A tool to abuse Exchange services

ntlm relay attack to Exchange Web Services

Enumerate valid users on Office 365 and Exchange via time-based and error-based techniques across multiple exposed services, including OWA,…

Identify public-facing Microsoft Exchange servers and determine their software versions

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Dockerized mail server suite with Postfix, Dovecot, Rspamd, and ClamAV. Provides secure email hosting with integrated spam filtering, antivirus, and…

Real-time cloud-native runtime security agent for Linux that monitors syscalls and container/Kubernetes metadata to detect anomalous behavior and…

A toolkit to attack Office365

Repository of attack and defensive information for Business Email Compromise investigations

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

Microsoft Entra ID (Azure AD) Unauthenticated Enumeration

Open source tooling to stop ICS phishing (malicious calendar invites)

Tuning and refactoring Google Chronicle Curated Detections to eliminate alert fatigue and fix logic gaps/bugs.

PowerShell-based detection and remediation toolkit for CVE-2025-32711 (EchoLeak), a critical zero-click AI command injection vulnerability in…