
StalkPhish
Open-source tool for harvesting and analyzing phishing kits to support threat intelligence, incident response, and phishing investigations.

Open-source tool for harvesting and analyzing phishing kits to support threat intelligence, incident response, and phishing investigations.

A Python tool for ingesting HTML and producing HTML source suitable for phishing campaigns.

Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…

Automated social engineering phishing framework for rapid reconnaissance, email target harvesting, and deployment of phishing websites in security…

Intelligent threat hunter and phishing servers

Phishing tool targeting lock screens to capture Windows credentials, Android PINs, and iPhone passcodes via HTTPS links with automatic device…

Automated phishing email tool with LinkedIn email harvesting, Gmail authentication, and web portal cloning for credential theft during social…

OSINT tool that detects domain squatting, typosquatting, and phishing look-alikes by monitoring newly registered domains against brand keywords with…

Automated Twitter phishing tool that collects target data, identifies friends, and generates spoofed tweets using Markov chain algorithms for social…

This tool is based on regex with effective standards for detecting phishing sites in real time using certstream and can also detect punycode (IDNA)…

An evil RAT (Remote Administration Tool) for macOS / OS X.

Generate and test domain typos and variations to detect and perform typo squatting, URL hijacking, phishing, and corporate espionage.

Detects active domain mutations to prevent phishing and smishing. Uses IANA TLDs, blockchain DNS validation, and DoH malware reports. Outputs JSON or…

HiddenEye Reborn in better shape than ever, rewritten from scratch and adapted to modern world

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names

Message-queue-based threat intelligence feed collector and processor for CSIRTs. Automates ingestion, normalization, and sharing of security…

abusing windows toast notifications for fun and user manipulation
