
Red-Teaming-Toolkit
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs

XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.

Serverless AITM Simulation Framework for Entra ID and M365

ShadowPhish is an advanced APT awareness toolkit designed to simulate real-world phishing, malware delivery, deepfakes, smishing/vishing, and command…

This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution,…

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)

A practical chain that starts with an innocuous PDF file and ends up in a reverse shell on an AWS EC2 instance

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

evilginx3 + gophish

↕️🤫 Stealth redirector for your red team operation security

CVE-2025-33053 Proof Of Concept (PoC)

CVE-2019-12949

Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.

DEPRECATED, wifipumpkin3 -> https://github.com/P0cL4bs/wifipumpkin3