
https-github.com-xaitax-CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability
Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

Finding all things on-prem Microsoft for password spraying and enumeration.

Identifying and Mitigating the CVE-2020–0796 flaw in the fly

Quick tool for checking CVE-2020-0688 on multiple hosts with a non-intrusive method.

CVE-2022-41040 - Server Side Request Forgery (SSRF) in Microsoft Exchange Server

Exploit chain for CVE-2021-26855 and CVE-2021-27065 targeting Microsoft Exchange Server, enabling authentication bypass and remote code execution via…

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

This script test the CVE-2021-26855 vulnerability on Exchange Server.

Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive and hardening…

Microsoft signed ActiveDirectory PowerShell module

Send phishing messages and attachments to Microsoft Teams users

A tool for checking if MFA is enabled on multiple Microsoft Services

SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY,…

A password spraying tool for Microsoft Online accounts (Azure/O365). The script logs if a user cred is valid, if MFA is enabled on the account, if a…

PXEThief is a set of tooling that can extract passwords from the Operating System Deployment functionality in Microsoft Endpoint Configuration Manager

A command shell wrapper using only WMI for Microsoft Windows

Collection of offensive tools targeting Microsoft Azure

Find Microsoft Exchange instance for a given domain and identify the exact version