
EmailXpose
EmailXpose is an open source AI-powered email security system that detects phishing, spam, scams, malware, and social engineering attacks. It goes…

EmailXpose is an open source AI-powered email security system that detects phishing, spam, scams, malware, and social engineering attacks. It goes…

Community-maintained dataset of 700+ websites for finding accounts by username — powers OSINT and digital footprint tools.

Automated WPA/WPA2 phishing tool that captures handshakes, spawns a rogue access point, and lures users to a captive portal to harvest credentials…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

camjacking templates

Track the GPS location of the user's smartphone or PC and capture a picture of the target, along with IP and device information.

Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

Demonstrates capturing NTLM hashes via Responder and executing phishing emails exploiting CVE-2024-21413 to compromise systems.

An OSINT Geolocalization tool for Telegram that find nearby users and groups 📡🌍🔍

CVE-2021-46366: Credential Bruteforce Attack via CSRF + Open Redirect in Magnolia CMS

Send phishing messages and attachments to Microsoft Teams users

PHP library for executing Telegram OSINT scenarios: search users, parse group members, monitor online status, download photos, and track profile…

CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification…

An advanced Twitter scraping & OSINT tool written in Python that doesn't use Twitter's API, allowing you to scrape a user's followers, following,…

Most Powerful Send Fake Mail Using Any Mail I'd undetectable

telegram bug that discloses user's hidden phone number (still unpatched) (exploit included)

Creates Fake Auth prompt to capture users plaintext passwords