
Awesome-BEC
Repository of attack and defensive information for Business Email Compromise investigations

Repository of attack and defensive information for Business Email Compromise investigations

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

A tool for mapping cyber crime

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

Real-time phishing campaign back-office plugin for Zphisher, capturing credentials, checking account exposure via haveibeenpwned, and evaluating…

Weaponizes Selenium to automate credential theft, cookie dumping, email exfiltration, and file extraction from Chromium browsers for red team…

Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens

Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.

Bella is a pure python post-exploitation data mining tool & remote administration tool for macOS. 🍎💻

Modified CVE-2022-30190 exploit tool for MS-MSDT Office RCE with custom docx template support, binary/command execution modes, and embedded HTTP…

Python Script for Email Bombing which supports Gmail, Yahoo, Hotmail/Outlook

A testing framework for mail security and filtering solutions.

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

Technical write-up and proof-of-concept for CVE-2022-44666, a Windows Contacts syslink control href attribute escape vulnerability enabling remote…

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

A simple script to generate a hidden url for social engineering.

MCP server for Google search and page fetching using headless Chromium

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…