
beef
The Browser Exploitation Framework Project

The Browser Exploitation Framework Project

Purple team project exploiting CVE-2023-23397 Outlook NTLM leak with phishing delivery, plus Sigma/Wazuh detections mapped to MITRE ATT&CK for the…

Educational cybersecurity project demonstrating exploitation and mitigation of CVE-2020-25213 (WordPress File Manager Plugin RCE). Includes malware…

Proof-of-concept security demo illustrating how PowerShell can create trusted-looking Windows toast notifications chained together with…

Proof-of-concept exploit for CVE-2026-20841, a Windows Notepad remote code execution vulnerability, using a crafted .md file and social engineering…

Discovering CVE-2025-22381: Host Header Injection in the Aggie Open-Source Project

This is Advance Phishing Tool ! OTP PHISHING

Automated container orchestration tool for Browser-in-the-Browser (BITB) phishing attacks, enabling red teams to scale multi-target infrastructure…

Proof of concept for stored HTML injection in RISE CRM, demonstrating how authenticated users can inject malicious HTML into invoices and messages,…

CVE-2024-27474, CVE-2024-27476, CVE-2024-27477

Proof-of-concept for a blind XSS vulnerability in Maid Hiring Management System v1.0, capturing admin session cookies via a crafted application form…

Demonstrates capturing NTLM hashes via Responder and executing phishing emails exploiting CVE-2024-21413 to compromise systems.

HiddenEye Reborn in better shape than ever, rewritten from scratch and adapted to modern world

Analyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries,…

StalkPhish - The Phishing kits stalker, harvesting phishing kits for investigations.

PoC of the phishing through setting browser in the fullscreen mode

📱 🐟 An app to remote control SocialFish.

🐈Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中