
TokenTacticsV2
A fork of the great TokenTactics with support for CAE and token endpoint v2

A fork of the great TokenTactics with support for CAE and token endpoint v2

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

Azure JWT Token Manipulation Toolset

PowerShell proof-of-concept for CVE-2023-23397 that exploits Outlook's ReminderSoundFile property to intercept Net-NTLMv2 hashes via SMB or WebDAV…

Proof-of-concept for CVE-2026-22005 showing OAuth 2.0 device code phishing via too-short polling interval, with vulnerable Flask server and exploit…

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

evilginx3 + gophish

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2


Advanced phishing tool combining OAuth Device Code authentication flow with QR codes to harvest Microsoft authentication tokens via MFA update…

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

Modlishka. Reverse Proxy.

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow