
blindxss-lite
A lightweight Blind XSS (Cross-Site Scripting) collector and payload server built with Flask

A lightweight Blind XSS (Cross-Site Scripting) collector and payload server built with Flask

Dependency-free Python PoC generator for CVE-2025-24071 that crafts a malicious .library-ms file in a ZIP to trigger Windows Explorer NTLM hash…

Valid JQuery that profiles the system and returns info to the server in a fake analytics GET request

Modular phishing framework with CLI for cloning sites, sending templated emails, and launching phishing campaigns via email, SMS, iMessage, and…

A script that helps you understand why your E-Mail ended up in Spam

C# Tool to interact with MS Exchange based on MS docs

Actively hunt for attacker infrastructure by filtering Shodan results with URLScan data.

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

A tool for mapping cyber crime

TryHackMe Moniker Link (CVE-2024-21413) walkthrough: Outlook Protected View bypass leading to NTLMv2 hash capture via a crafted moniker link.

The Outlook HTML Leak Test Project

Example on how to injection(currently under work) of keylogger js through Safari Extension(that part done)

CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

a SET framework templates

Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens


Self contained htaccess shells and attacks

CVE Reproduction: cve-2024-43451-ntlm_hash_disclosure_reproduction