
PRISM-AP
An automated Wireless RogueAP MITM attack framework.

An automated Wireless RogueAP MITM attack framework.

Open-source tracking framework that generates configurable tracking images and links for email, web, and chat systems, with a hacker-friendly…


Real-time phishing platform that bypasses 2FA via a live noVNC browser session, capturing cookies, saved passwords, browsing history, and downloaded…

An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents

Multi-purpose penetration testing framework bundling tools for information gathering, web hacking, password attacks, phishing, malware creation,…

Harvests NetNTLM hashes in Windows domains via a local WebDAV server, with LNK file poisoning and Office document field code injection for lateral…

VPN Overall Reconnaissance, Testing, Enumeration and eXploitation Toolkit

A Python script to collect campaign data from Gophish and generate a report

Python library for detecting homoglyphs, converting Unicode to ASCII, and identifying languages/scripts. Useful for OSINT, domain discovery, and…

Collection of offensive tools targeting Microsoft Azure

Pre-built social engineering templates for the Social Engineering Toolkit (SET), including phishing, pretexting, and credential harvesting scenarios…

Proof-of-concept exploit for CVE-2024-21413 (MonikerLink) enabling remote code execution and NTLM credential leakage via crafted email links,…

Real-time phishing campaign back-office plugin for Zphisher, capturing credentials, checking account exposure via haveibeenpwned, and evaluating…

Proof of concept for a stored cross-site scripting (XSS) vulnerability in SeedDMS 6.0.29, demonstrating injection via the category name field and…

Send phishing messages and attachments to Microsoft Teams users

Find phishing kits which use your brand/organization's files and image.

Self contained htaccess shells and attacks