
Abused-Legitimate-Services
Cloud, CDN, and marketing services leveraged by cybercriminals and APT groups

Cloud, CDN, and marketing services leveraged by cybercriminals and APT groups

This repository contains indicators of compromise (IOCs) of our various investigations.

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security…

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

A toolkit to attack Office365

Snoopy: A distributed tracking and data interception framework

Automated phishing campaign toolset that spawns dedicated AWS EC2 instances with integrated PhishingFrenzy and BeEF, plus subdomain discovery and…

Serverless AITM Simulation Framework for Entra ID and M365

Cloud Exploit Framework

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

Kali365 - EvilTokens Replica

Open source tooling to stop ICS phishing (malicious calendar invites)

Wiki to collect Red Team infrastructure hardening resources

Deploy a phishing infrastructure on the fly.