
I-See-You
ISeeYou is a Bash and Javascript tool to find the exact location of the users during social engineering or phishing engagements. Using exact location…

ISeeYou is a Bash and Javascript tool to find the exact location of the users during social engineering or phishing engagements. Using exact location…

Credsleaker allows an attacker to craft a highly convincing credentials prompt using Windows Security, validate it against the DC and in turn leak it…

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

Actively hunt for attacker infrastructure by filtering Shodan results with URLScan data.

Simple PoC in PowerShell for CVE-2023-23397

POC Jamovi <=1.6.18 is affected by a cross-site scripting (XSS) vulnerability. The column-name is vulnerable to XSS in the ElectronJS Framework. An…

CVE-2018-25031 tests

an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

Cross Site Scripting vulnerability in mooSocial mooSocial Software v.3.1.6 allows a remote attacker to execute arbitrary code via a crafted script to…

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

A simple POC (CVE-2018-25031

xll windows reverse shell

All-in-One WP Migration < 7.63 - Unauthenticated Reflected XSS + CSRF

(DOM-based XSS) HTML Injection vulnerability in TOWeb v.12.05 and before allows an attacker to inject HTML/JS code via the _message.html component.