
ThePhish
Automated phishing email analysis tool integrating TheHive, Cortex, and MISP to extract observables, run analyzers, calculate verdicts, and notify…

Automated phishing email analysis tool integrating TheHive, Cortex, and MISP to extract observables, run analyzers, calculate verdicts, and notify…

Open-source URL masking & analysis tool for security research, phishing awareness, and defensive testing. Demonstrates adversary techniques used to…

People tracker on the Internet: OSINT analysis and research tool by Jose Pino

Hybrid ML and heuristic-based URL phishing detector with real-time analysis, explainable confidence scores, and REST API for programmatic security…

Advanced phishing tool combining OAuth Device Code authentication flow with QR codes to harvest Microsoft authentication tokens via MFA update…

A python server tool based on flask , this tool can phish some Facebook credentials!

Real-time two-factor phishing tool that automates credential harvesting by intercepting credentials from a phishing site and submitting them to the…

Transparent reverse proxy for penetration testing that bypasses 2FA, harvests credentials, and proxies multi-domain TLS traffic without client…

Automated phishing toolkit with pre-built login page templates and multiple port forwarding options (Ngrok, Serveo) for credential harvesting and…

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

Tools and Techniques for Red Team / Penetration Testing

HTML/CSS/JS templates for Browser-In-The-Browser phishing attacks, embedding fake login windows with customizable titles, domains, and phishing links…

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

Targeted evil twin attacks against WPA2-Enterprise networks. Indirect wireless pivots using hostile portal attacks.

Phishing framework with Flask backend that clones login pages and captures credentials along with 2FA tokens, featuring SSL support and an API for…

An SSL Enabled Basic Auth Credential Harvester with a Word Document Template URL Injector

OTP BOT Bypass SMS verifications from Paypal, Instagram, Snapchat, Google, 3D Secure, and many others...