
ExchangeRelayX
An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

ISeeYou is a Bash and Javascript tool to find the exact location of the users during social engineering or phishing engagements. Using exact location…

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

Credsleaker allows an attacker to craft a highly convincing credentials prompt using Windows Security, validate it against the DC and in turn leak it…

(DOM-based XSS) HTML Injection vulnerability in TOWeb v.12.05 and before allows an attacker to inject HTML/JS code via the _message.html component.

A simple POC (CVE-2018-25031


CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.


an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

Cross Site Scripting vulnerability in mooSocial mooSocial Software v.3.1.6 allows a remote attacker to execute arbitrary code via a crafted script to…

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

Simple PoC in PowerShell for CVE-2023-23397

All-in-One WP Migration < 7.63 - Unauthenticated Reflected XSS + CSRF

CVE-2018-25031 tests

xll windows reverse shell

POC Jamovi <=1.6.18 is affected by a cross-site scripting (XSS) vulnerability. The column-name is vulnerable to XSS in the ElectronJS Framework. An…

Actively hunt for attacker infrastructure by filtering Shodan results with URLScan data.