
hackingtool
All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Kali365 - EvilTokens Replica

A toolkit to attack Office365

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

The SOC Analysts all-in-one CLI tool to automate and speed up workflow.

A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security…

Open source tooling to stop ICS phishing (malicious calendar invites)

CATPHISH project - For phishing and corporate espionage. Perfect for RED TEAM.

Automated phishing campaign toolset that spawns dedicated AWS EC2 instances with integrated PhishingFrenzy and BeEF, plus subdomain discovery and…

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

Cloud Exploit Framework

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

Detects active domain mutations to prevent phishing and smishing. Uses IANA TLDs, blockchain DNS validation, and DoH malware reports. Outputs JSON or…

Serverless AITM Simulation Framework for Entra ID and M365