
king-phisher
Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

Open-source interactive security awareness training library with 130+ SCORM exercises covering phishing, vishing, BEC, MFA fatigue, and OWASP AI/LLM…

Security awareness training tool for authorized phishing simulations and internal IT audits

A lightweight, self-hosted simulation tool for "ClickFix" (ClearFake) social engineering training. Safely simulates clipboard-injection attacks with…

Powerful framework for rogue access point attack.

Automates Illicit Consent Grant attacks against Azure/O365 tenants to steal refresh tokens, exfiltrate emails/OneDrive data, and create malicious…

A security vulnerability has been identified in Krayin CRM <=2.1.0 that allows a low-privileged user to escalate privileges by tricking an admin into…

Proof-of-concept exploit demonstrating HTML injection in SOGo Web Client before 5.9.1, enabling phishing attacks via malicious forms in email bodies.

Automated WPA/WPA2 phishing tool that captures handshakes, spawns a rogue access point, and lures users to a captive portal to harvest credentials…

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

This repository contains POC scenarios as part of CVE-2025-0411 MotW bypass.

evilginx3 + gophish

Generates a malicious Microsoft Word document exploiting the MS-MSDT 'Follina' vulnerability to execute arbitrary commands or stage payloads via an…

Weaponized Browser-in-the-Middle (BitM) for Penetration Testers

Ruby on Rails Phishing Framework

An SSL Enabled Basic Auth Credential Harvester with a Word Document Template URL Injector

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.