
CVE-2025-50363_BXSS_CVE
Proof-of-concept for a blind XSS vulnerability in Maid Hiring Management System v1.0, capturing admin session cookies via a crafted application form…

Proof-of-concept for a blind XSS vulnerability in Maid Hiring Management System v1.0, capturing admin session cookies via a crafted application form…

CVE-2024-27474, CVE-2024-27476, CVE-2024-27477

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

Red team operations management platform automating infrastructure deployment, C2 setup, phishing campaigns, and reconnaissance with integrated tool…

A toolkit to attack Office365

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

ThePhish: an automated phishing email analysis tool

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

This repository contains indicators of compromise (IOCs) of our various investigations.

Entra ID user enumeration and auth method discovery via the public GetCredentialType API

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

Open-source threat intelligence platform for malware and observable analysis. Enriches IPs, domains, URLs, and hashes with external sources, performs…

Open source tooling to stop ICS phishing (malicious calendar invites)

Proof-of-concept for CVE-2026-22005 showing OAuth 2.0 device code phishing via too-short polling interval, with vulnerable Flask server and exploit…

StalkPhish - The Phishing kits stalker, harvesting phishing kits for investigations.