
scambuster
Defensive engagement & threat intelligence research laboratory. Converts inbound scam emails into actionable IOCs through controlled, policy-driven…

Defensive engagement & threat intelligence research laboratory. Converts inbound scam emails into actionable IOCs through controlled, policy-driven…

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

PhEmail is a python open source phishing email tool that automates the process of sending phishing emails as part of a social engineering test

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

Tools and Techniques for Red Team / Penetration Testing

Advanced Phishing tool

HTML/CSS/JS templates for Browser-In-The-Browser phishing attacks, embedding fake login windows with customizable titles, domains, and phishing links…

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

Targeted evil twin attacks against WPA2-Enterprise networks. Indirect wireless pivots using hostile portal attacks.

🐈Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中

FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule…

ThePhish: an automated phishing email analysis tool

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

An SSL Enabled Basic Auth Credential Harvester with a Word Document Template URL Injector

Bulk domain spoofability checker using authoritative SPF and DMARC record analysis with custom, real-world tested spoof logic and optional DKIM…

Weaponized Browser-in-the-Middle (BitM) for Penetration Testers

An open-source Secure Email Gateway (SEG) evaluation toolkit designed for red-teamers.