
subfinder
Fast passive subdomain enumeration tool.

Fast passive subdomain enumeration tool.

E-mails, subdomains and names Harvester - OSINT

Automated WPA/WPA2 phishing tool that captures handshakes, spawns a rogue access point, and lures users to a captive portal to harvest credentials…

Multi-purpose WiFi penetration testing toolkit for M5Stack devices. Performs network scanning, evil-twin attacks, deauthentication, captive portal…

Dependency-free Python PoC generator for CVE-2025-24071 that crafts a malicious .library-ms file in a ZIP to trigger Windows Explorer NTLM hash…

SSH-MITM - ssh audits made simple

A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Frameless Browser‑in‑the‑Browser (BitB) - No iframes, no frame‑busting issues. A single‑script Shadow DOM / MutationObserver library for realistic…

Modlishka. Reverse Proxy.

A font-based deception tool for red teaming, security research, and whatever else.

Educational trojan simulator for cybersecurity training, simulating phishing attacks with social engineering, system reconnaissance, anti-sandbox…

Remote operations commands implemented using Beacon Object Files

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…