
TLDHunt
Bash-based domain availability checker that scans WHOIS records across multiple TLDs to find unregistered domains for red teaming and phishing…

Bash-based domain availability checker that scans WHOIS records across multiple TLDs to find unregistered domains for red teaming and phishing…

A Slack bot phishing framework for Red Teaming exercises

Intelligent threat hunter and phishing servers

Potential malicious code execution via CHM hijacking (CVE-2019-9896)

crawls the website and finds broken social media links that can be hijacked

real time face swap and one-click video deepfake with only a single image

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

HTML/CSS/JS templates for Browser-In-The-Browser phishing attacks, embedding fake login windows with customizable titles, domains, and phishing links…

Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

Windows credential harvester that displays a fake logon screen, validates captured passwords against AD or local machine, and outputs them to console…

An SSL Enabled Basic Auth Credential Harvester with a Word Document Template URL Injector

Phishing with a fake reCAPTCHA

transform your payload.exe into one fake word doc (.ppt)
