
CVE-2023-51764
Postfix SMTP Smuggling - Expect Script POC

Postfix SMTP Smuggling - Expect Script POC

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

PhEmail is a python open source phishing email tool that automates the process of sending phishing emails as part of a social engineering test

EmailXpose is an open source AI-powered email security system that detects phishing, spam, scams, malware, and social engineering attacks. It goes…

Open source tooling to stop ICS phishing (malicious calendar invites)

Super organized and flexible script for sending phishing campaigns

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

ThePhish: an automated phishing email analysis tool

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

Tools and Techniques for Red Team / Penetration Testing

HTML/CSS/JS templates for Browser-In-The-Browser phishing attacks, embedding fake login windows with customizable titles, domains, and phishing links…

Bulk domain spoofability checker using authoritative SPF and DMARC record analysis with custom, real-world tested spoof logic and optional DKIM…

Advanced phishing tool combining OAuth Device Code authentication flow with QR codes to harvest Microsoft authentication tokens via MFA update…

OTP BOT Bypass SMS verifications from Paypal, Instagram, Snapchat, Google, 3D Secure, and many others...

🐈Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中