
EvilSelenium
Weaponizes Selenium to automate credential theft, cookie dumping, email exfiltration, and file extraction from Chromium browsers for red team…

Weaponizes Selenium to automate credential theft, cookie dumping, email exfiltration, and file extraction from Chromium browsers for red team…

ntlm relay attack to Exchange Web Services

警惕 一种针对红队的新型溯源手段!

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

Bash script to check if a domain or list of domains can be spoofed based in DMARC records


Find phishing kits which use your brand/organization's files and image.

A testing framework for mail security and filtering solutions.

A Python script to collect campaign data from Gophish and generate a report

A tool for mapping cyber crime

Don't Just Search OSINT. Sweep It.

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

Real-time phishing campaign back-office plugin for Zphisher, capturing credentials, checking account exposure via haveibeenpwned, and evaluating…

IP-Biter: The Hacker-friendly E-Mail (but not only) Tracking Framework

Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens

An automated Wireless RogueAP MITM attack framework.

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

Collection of offensive tools targeting Microsoft Azure