
CVE-2023-41425-RCE-WonderCMS-4.3.2
Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

A basic phishing kit scanner for dedicated and semi-dedicated hosting

Bash script to check if a domain or list of domains can be spoofed based in DMARC records

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

C# Tool to interact with MS Exchange based on MS docs

A python server tool based on flask , this tool can phish some Facebook credentials!

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

A PowerShell based utility for the creation of malicious Office macro documents.

ThePhish: an automated phishing email analysis tool

XLL Phishing Tradecraft

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

Most Powerful Send Fake Mail Using Any Mail I'd undetectable

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

Lightweight Agent Detection & Response (ADR) layer for AI agents — guards commands, files, and web requests. Part of Gen Agent Trust Hub.