
Deep-Live-Cam
real time face swap and one-click video deepfake with only a single image

real time face swap and one-click video deepfake with only a single image

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Frameless Browser‑in‑the‑Browser (BitB) - No iframes, no frame‑busting issues. A single‑script Shadow DOM / MutationObserver library for realistic…

Modlishka. Reverse Proxy.

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

Proof-of-concept exploit for CVE-2025-26788 demonstrating WebAuthn credential ID manipulation via JavaScript hooking to bypass authentication in…

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

AI-powered LinkedIn engagement assistant

SEt framework

Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

Automates phishing and post-phishing activities with an almost-transparent reverse proxy that dynamically mirrors target web apps and interacts with…

Phishing with a fake reCAPTCHA


Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…