
I-See-You
ISeeYou is a Bash and Javascript tool to find the exact location of the users during social engineering or phishing engagements. Using exact location…

ISeeYou is a Bash and Javascript tool to find the exact location of the users during social engineering or phishing engagements. Using exact location…

Credsleaker allows an attacker to craft a highly convincing credentials prompt using Windows Security, validate it against the DC and in turn leak it…

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

ntlm relay attack to Exchange Web Services

Security awareness training tool for authorized phishing simulations and internal IT audits

In LetterPress plugin <= 1.2.1 is vulnerable to Html Injection Vulnerability which can futher leads to Open Redirection Vulnerabilty.

Generate Gmail Emailing Keyloggers to Windows.

Modular phishing framework with CLI for cloning sites, sending templated emails, and launching phishing campaigns via email, SMS, iMessage, and…

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

Morpheus - Automating Ettercap TCP/IP (MITM-hijacking Tool)

Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)

CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

Potential malicious code execution via CHM hijacking (CVE-2019-9896)

Clone and import Chromium cookies and passwords across browsers with offline DPAPI state key decryption, supporting AES-256 GCM encrypted databases…

Lockphish it's the first tool (07/04/2020) for phishing attacks on the lock screen, designed to grab Windows credentials, Android PIN and iPhone…

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…