
demiguise
HTA encryption tool for RedTeams

HTA encryption tool for RedTeams

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)

Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

Real-time phishing platform that bypasses 2FA via a live noVNC browser session, capturing cookies, saved passwords, browsing history, and downloaded…

Excel 4.0 (XLM) Macro Generator for injecting DLLs and EXEs into memory.

Collection of scripts to aid in delivering payloads via Office Macros. Most are python. See http://khr0x40sh.wordpress.com for details.

A fork of the great TokenTactics with support for CAE and token endpoint v2

An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents

Weaponized Browser-in-the-Middle (BitM) for Penetration Testers

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…

Generate obfuscated Excel 4.0 XLM macros for red team operations and blue team analysis, with support for multiple infection techniques, formula…
