
DefinitelyNotPhishing
Contains evilginx phislets, gophish templates, burp suite extensions etc.

Contains evilginx phislets, gophish templates, burp suite extensions etc.

Valid JQuery that profiles the system and returns info to the server in a fake analytics GET request

Deploy a phishing infrastructure on the fly.

Exploit PoC for CVE-2026-27579, a CORS misconfiguration in Appwrite backend, demonstrating credentialed account data theft via malicious phishing…

CVE-2024-4367 is a critical vulnerability (CVSS 9.8) in PDF.js, allowing arbitrary JavaScript code execution due to insufficient type checks on the…

Automates phishing and post-phishing activities with an almost-transparent reverse proxy that dynamically mirrors target web apps and interacts with…

Documentation of my hands-on lab Moniker Link (CVE-2024-21413) completed on TryHackMe.

Spoof emails from any of the +2 Million domains using MailChannels (DEFCON 31 Talk)

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Phishing with a fake reCAPTCHA

A tool for mapping cyber crime

TryHackMe Moniker Link (CVE-2024-21413) walkthrough: Outlook Protected View bypass leading to NTLMv2 hash capture via a crafted moniker link.

Proof-of-concept for CVE-2026-22005 showing OAuth 2.0 device code phishing via too-short polling interval, with vulnerable Flask server and exploit…

Phishing simulation and awareness framework for node-based campaigns, credential capture, SMTP delivery, CAPTCHA, and optional browser credential…

Emulates a Cisco ASA Anyconnect VPN service for credential harvesting and VBS payload delivery in red team phishing operations.

The Outlook HTML Leak Test Project

Scripts to clone CA certificates for use in HTTPS client attacks.

xll windows reverse shell