
365-Stealer
Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

A tool to transform Chromium browsers into a C2 Implant

HiddenEye Reborn in better shape than ever, rewritten from scratch and adapted to modern world

A new approach to Browser In The Browser (BITB) without the use of iframes, allowing the bypass of traditional framebusters implemented by login…

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

Generate and test domain typos and variations to detect and perform typo squatting, URL hijacking, phishing, and corporate espionage.

A Phishing Dropper designed to Pentest.

Advanced phishing tool combining OAuth Device Code authentication flow with QR codes to harvest Microsoft authentication tokens via MFA update…

Spoof SSDP replies and create fake UPnP devices to phish for credentials and NetNTLM challenge/response.

A Python script to collect campaign data from Gophish and generate a report

A quick handy script to harvest credentials off of a user during a Red Team and get execution of a file from the user

Open source Android, iOS and Web app for learning about and managing digital and physical security. From how to send a secure message to dealing with…

Educational phishing simulation tool that mimics OS login screens to capture credentials for cybersecurity awareness training. Supports Windows,…

Phishing Simulation mainly aims to increase phishing awareness by providing an intuitive tutorial and customized assessment

New 0 day vulnerability allowing to leak NTLM hashes from browsers with one click

Injects JavaScript keylogger into WebView2 pages to capture keystrokes and exfiltrate cookies from Microsoft authentication sessions via HTTP GET…

ShadowPhish is an advanced APT awareness toolkit designed to simulate real-world phishing, malware delivery, deepfakes, smishing/vishing, and command…

Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…