
Deep-Live-Cam
real time face swap and one-click video deepfake with only a single image

real time face swap and one-click video deepfake with only a single image

Automates phishing and post-phishing activities with an almost-transparent reverse proxy that dynamically mirrors target web apps and interacts with…

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

Frameless Browser‑in‑the‑Browser (BitB) - No iframes, no frame‑busting issues. A single‑script Shadow DOM / MutationObserver library for realistic…

Modlishka. Reverse Proxy.

Repository for CVE-2023-4549 vulnerability.

Advanced Phishing tool

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…


HTML/CSS/JS templates for Browser-In-The-Browser phishing attacks, embedding fake login windows with customizable titles, domains, and phishing links…

Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…

Advanced phishing tool combining OAuth Device Code authentication flow with QR codes to harvest Microsoft authentication tokens via MFA update…

Spoof emails from any of the +2 Million domains using MailChannels (DEFCON 31 Talk)

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

transform your payload.exe into one fake word doc (.ppt)

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.