
O365-Doppelganger
A quick handy script to harvest credentials off of a user during a Red Team and get execution of a file from the user

A quick handy script to harvest credentials off of a user during a Red Team and get execution of a file from the user

Powerful framework for rogue access point attack.

Automated WPA/WPA2 phishing tool that captures handshakes, spawns a rogue access point, and lures users to a captive portal to harvest credentials…

Ruby on Rails Phishing Framework

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

Rogue access point toolkit for WiFi penetration testing, deploying evil portal phishing payloads to capture credentials and perform social…

Creates Fake Auth prompt to capture users plaintext passwords

Proof-of-concept exploit for CVE-2018-13257 demonstrating CAS host header spoofing in Blackboard Learn to hijack user sessions via a malicious…

Powershell script to create malicious SMB or WebDAV links to steal NTLM authentication

Wiki to collect Red Team infrastructure hardening resources

Red team operations management platform automating infrastructure deployment, C2 setup, phishing campaigns, and reconnaissance with integrated tool…

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

Tools and Techniques for Red Team / Penetration Testing

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

Real-time phishing platform that bypasses 2FA via a live noVNC browser session, capturing cookies, saved passwords, browsing history, and downloaded…

↕️🤫 Stealth redirector for your red team operation security

CATPHISH project - For phishing and corporate espionage. Perfect for RED TEAM.