
sublime-rules
Sublime rules for email attack detection, prevention, and threat hunting.

Sublime rules for email attack detection, prevention, and threat hunting.

Detailed vulnerability assessment and exploitation report for CVE-2024-21413 (Moniker Link) in Microsoft Outlook, including attack path, NetNTLMv2…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Generate unicode domains for IDN Homograph Attack and detect them.

Spam filtering and email processing framework with regex rules, statistical analysis, custom Lua plugins, and external blocklists for MTA integration.

The SOC Analysts all-in-one CLI tool to automate and speed up workflow.

Powerful framework for rogue access point attack.

ThePhish: an automated phishing email analysis tool

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

Automated man-in-the-middle attack tool.

Proof-of-concept exploit for Microsoft Outlook RCE (CVE-2024-21413) with SMTP-based phishing email delivery, malicious RTF attachment generation, and…

Social engineering attack vector and exploitation framework for hijacking user sessions via QR code login, targeting web applications like WhatsApp,…

Documentation of CVE-2024-50964: critical DMARC policy bypass in DonWeb MX server allowing email spoofing, with low attack complexity and no required…

Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they…

Automated WPA/WPA2 phishing tool that captures handshakes, spawns a rogue access point, and lures users to a captive portal to harvest credentials…

PowerShell toolkit for remote template injection attacks and defense. Injects malicious links into Office Word documents for phishing, with…

Addressbar spoofing through blob URL (Firefox browser). An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by…