

The Browser Exploitation Framework Project

This is Advance Phishing Tool ! OTP PHISHING

🐈Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中

Framework for Man-In-The-Middle attacks

HiddenEye Reborn in better shape than ever, rewritten from scratch and adapted to modern world

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…

Proof-of-concept security demo illustrating how PowerShell can create trusted-looking Windows toast notifications chained together with…

CATPHISH project - For phishing and corporate espionage. Perfect for RED TEAM.

📱 🐟 An app to remote control SocialFish.

Proof-of-concept exploit for CVE-2026-20841, a Windows Notepad remote code execution vulnerability, using a crafted .md file and social engineering…

StalkPhish - The Phishing kits stalker, harvesting phishing kits for investigations.

Educational cybersecurity project demonstrating exploitation and mitigation of CVE-2020-25213 (WordPress File Manager Plugin RCE). Includes malware…

Purple team project exploiting CVE-2023-23397 Outlook NTLM leak with phishing delivery, plus Sigma/Wazuh detections mapped to MITRE ATT&CK for the…

Demonstrates capturing NTLM hashes via Responder and executing phishing emails exploiting CVE-2024-21413 to compromise systems.

Proof of concept for stored HTML injection in RISE CRM, demonstrating how authenticated users can inject malicious HTML into invoices and messages,…

XLL Phishing Tradecraft

CVE-2024-27474, CVE-2024-27476, CVE-2024-27477