
Penetration-Testing-Tools
A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security…

A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security…

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

Serverless AITM Simulation Framework for Entra ID and M365

Open source tooling to stop ICS phishing (malicious calendar invites)

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

Automated phishing campaign toolset that spawns dedicated AWS EC2 instances with integrated PhishingFrenzy and BeEF, plus subdomain discovery and…

CATPHISH project - For phishing and corporate espionage. Perfect for RED TEAM.

A toolkit to attack Office365

The SOC Analysts all-in-one CLI tool to automate and speed up workflow.

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

Cloud Exploit Framework

Detects active domain mutations to prevent phishing and smishing. Uses IANA TLDs, blockchain DNS validation, and DoH malware reports. Outputs JSON or…

Kali365 - EvilTokens Replica

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…