
hackingtool
All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

Kali365 - EvilTokens Replica

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

Open source tooling to stop ICS phishing (malicious calendar invites)

Serverless AITM Simulation Framework for Entra ID and M365

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

The SOC Analysts all-in-one CLI tool to automate and speed up workflow.

A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security…

Cloud Exploit Framework

Detects active domain mutations to prevent phishing and smishing. Uses IANA TLDs, blockchain DNS validation, and DoH malware reports. Outputs JSON or…

A toolkit to attack Office365

CATPHISH project - For phishing and corporate espionage. Perfect for RED TEAM.

Automated phishing campaign toolset that spawns dedicated AWS EC2 instances with integrated PhishingFrenzy and BeEF, plus subdomain discovery and…