
DNSSpoof
A DNS spoofer tool written in Python3.

A DNS spoofer tool written in Python3.

Modlishka. Reverse Proxy.

Pass the Hash to a named pipe for token Impersonation

Manipulating and Abusing Windows Access Tokens.

Decrypt GlobalProtect configuration and cookie files.

A C# utility for interacting with SCOM

Windows token manipulation utility that lists, steals, and impersonates process or user tokens to execute commands as other users, leveraging…

Spoof SSDP replies and create fake UPnP devices to phish for credentials and NetNTLM challenge/response.

Clone and import Chromium cookies and passwords across browsers with offline DPAPI state key decryption, supporting AES-256 GCM encrypted databases…

real time face swap and one-click video deepfake with only a single image

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

HTML/CSS/JS templates for Browser-In-The-Browser phishing attacks, embedding fake login windows with customizable titles, domains, and phishing links…

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).

Phishing with a fake reCAPTCHA

RunasCs - Csharp and open version of windows builtin runas.exe