
TokenTacticsV2
A fork of the great TokenTactics with support for CAE and token endpoint v2

A fork of the great TokenTactics with support for CAE and token endpoint v2

Modlishka. Reverse Proxy.

Proof-of-concept for CVE-2026-22005 showing OAuth 2.0 device code phishing via too-short polling interval, with vulnerable Flask server and exploit…

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Proof-of-concept exploit for CVE-2025-26788 demonstrating WebAuthn credential ID manipulation via JavaScript hooking to bypass authentication in…

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

USBCoercer turns an ESP32 development board with native USB-OTG into an Ethernet-over-USB gadget capable of coercing proxy configuration via WPAD.

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

Azure JWT Token Manipulation Toolset


evilginx3 + gophish

Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…

Collection of tools to use with Azure Applications

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

Advanced phishing tool combining OAuth Device Code authentication flow with QR codes to harvest Microsoft authentication tokens via MFA update…

PowerShell proof-of-concept for CVE-2023-23397 that exploits Outlook's ReminderSoundFile property to intercept Net-NTLMv2 hashes via SMB or WebDAV…

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow