

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

Security awareness training tool for authorized phishing simulations and internal IT audits

Educational cybersecurity project demonstrating exploitation and mitigation of CVE-2020-25213 (WordPress File Manager Plugin RCE). Includes malware…

A security vulnerability has been identified in Krayin CRM <=2.1.0 that allows a low-privileged user to escalate privileges by tricking an admin into…

✉️ HTML Smuggling generator&obfuscator for your Red Team operations

A PoC exploit for CVE-2022-0165 - Page Builder KingComposer WordPress Plugin - ID Parameter Validation Bypass

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

evilginx3 + gophish

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

Hacking tools pack & backdoors generator.

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

Weaponized Browser-in-the-Middle (BitM) for Penetration Testers

A new approach to Browser In The Browser (BITB) without the use of iframes, allowing the bypass of traditional framebusters implemented by login…

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

XLL Phishing Tradecraft

PwnSTAR (Pwn SofT-Ap scRipt) - for all your fake-AP needs!

Serverless AITM Simulation Framework for Entra ID and M365