
GraphSpy
Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Frameless Browser‑in‑the‑Browser (BitB) - No iframes, no frame‑busting issues. A single‑script Shadow DOM / MutationObserver library for realistic…

Modlishka. Reverse Proxy.

Proof-of-concept for CVE-2026-22005 showing OAuth 2.0 device code phishing via too-short polling interval, with vulnerable Flask server and exploit…

A Python tool for ingesting HTML and producing HTML source suitable for phishing campaigns.

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).


Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

Security awareness training tool for authorized phishing simulations and internal IT audits

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

A lightweight tool designed to stop clickfix attacks by using clipboard formatting with execution surface checks

A tool for mapping cyber crime

Open-source URL masking & analysis tool for security research, phishing awareness, and defensive testing. Demonstrates adversary techniques used to…

This is Advance Phishing Tool ! OTP PHISHING

Bash-based domain availability checker that scans WHOIS records across multiple TLDs to find unregistered domains for red teaming and phishing…

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…