
ChromeAlone
A tool to transform Chromium browsers into a C2 Implant

A tool to transform Chromium browsers into a C2 Implant

Accurately Locate Smartphones using Social Engineering

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

Proof-of-concept exploit for CVE-2026-20841, a Windows Notepad remote code execution vulnerability, using a crafted .md file and social engineering…

The Browser Exploitation Framework Project

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

evilginx3 + gophish

Generates a malicious Microsoft Word document exploiting the MS-MSDT 'Follina' vulnerability to execute arbitrary commands or stage payloads via an…

XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.

Serverless AITM Simulation Framework for Entra ID and M365

CVE-2019-12949

Automated PoC exploit for CVE-2022-30190 (Follina) that generates malicious RTF/DOCX files abusing MSDT protocol to execute arbitrary commands and…

Proof-of-concept exploit for CVE-2018-13257 demonstrating CAS host header spoofing in Blackboard Learn to hijack user sessions via a malicious…

Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)

Detailed proof-of-concept and technical analysis for CVE-2026-2441, a Chrome CSS use-after-free vulnerability enabling sandboxed renderer RCE via…

DEPRECATED, wifipumpkin3 -> https://github.com/P0cL4bs/wifipumpkin3

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…