
Sooty
The SOC Analysts all-in-one CLI tool to automate and speed up workflow.

The SOC Analysts all-in-one CLI tool to automate and speed up workflow.

Automated container orchestration tool for Browser-in-the-Browser (BITB) phishing attacks, enabling red teams to scale multi-target infrastructure…

ISeeYou is a Bash and Javascript tool to find the exact location of the users during social engineering or phishing engagements. Using exact location…

Manage Android machines with pre-defined behaviors for Cyber Range environments.

Firework is a proof of concept tool to interact with Microsoft Workplaces creating valid files required for the provisioning process.

Detects active domain mutations to prevent phishing and smishing. Uses IANA TLDs, blockchain DNS validation, and DoH malware reports. Outputs JSON or…

This little tool is to calculate a MurmurHash value of a favicon to hunt phishing websites on the Shodan platform.

HiddenEye Reborn in better shape than ever, rewritten from scratch and adapted to modern world

Lockphish it's the first tool (07/04/2020) for phishing attacks on the lock screen, designed to grab Windows credentials, Android PIN and iPhone…

Introducing "URL Making Technology" to the world for the very FIRST TIME. Give a Mask to Phishing URL like a PRO.. A MUST have tool for Phishing.

Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…

PenBox - A Penetration Testing Framework - The Tool With All The Tools , The Hacker's Repo

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

Technical write-up on CVE-2024-21413 (Moniker Link vulnerability)

This repository contains POC scenarios as part of CVE-2025-0411 MotW bypass.

Demonstrates capturing NTLM hashes via Responder and executing phishing emails exploiting CVE-2024-21413 to compromise systems.