
evilgophish
evilginx3 + gophish

evilginx3 + gophish

Weaponized Browser-in-the-Middle (BitM) for Penetration Testers

A toolkit to attack Office365

🐈Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中

Hacking tools pack & backdoors generator.

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

Red team framework and multi-operator C2 platform with AI agents, malleable implants, rootkits, phishing engine, and 741 CLI commands covering the…

Herramienta ideal para el despliegue automatizado de un Rogue AP con capacidad de selección de plantilla + 2FA. No requiere de conexión cableada.

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

Automated phishing campaign toolset that spawns dedicated AWS EC2 instances with integrated PhishingFrenzy and BeEF, plus subdomain discovery and…

PwnSTAR (Pwn SofT-Ap scRipt) - for all your fake-AP needs!

Serverless AITM Simulation Framework for Entra ID and M365

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

Cloud Exploit Framework

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

Kali365 - EvilTokens Replica