
SpoofThatMail
Bash script to check if a domain or list of domains can be spoofed based in DMARC records

Bash script to check if a domain or list of domains can be spoofed based in DMARC records

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

A python server tool based on flask , this tool can phish some Facebook credentials!

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Most Powerful Send Fake Mail Using Any Mail I'd undetectable

ThePhish: an automated phishing email analysis tool

Script in Go that analyzes a list of passwords based on in its entropy and weak passwords from a dictionary. Useful for penetration tests and…

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

C# Tool to interact with MS Exchange based on MS docs

This tool is based on regex with effective standards for detecting phishing sites in real time using certstream and can also detect punycode (IDNA)…

A PowerShell based utility for the creation of malicious Office macro documents.

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

Weaponizes Selenium to automate credential theft, cookie dumping, email exfiltration, and file extraction from Chromium browsers for red team…

(DOM-based XSS) HTML Injection vulnerability in TOWeb v.12.05 and before allows an attacker to inject HTML/JS code via the _message.html component.

CVE-2024-30056 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability