
dmi-tcat
Digital Methods Initiative - Twitter Capture and Analysis Toolset

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

Proof-of-Concept for CVE-2024-52005: ANSI escape sequence injection in Git. Demonstrates incorrect 'not_affected' VEX claims in hardened container…

A collection of awesome penetration testing resources, tools and other shiny things

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

Automates phishing and post-phishing activities with an almost-transparent reverse proxy that dynamically mirrors target web apps and interacts with…

Open source Android, iOS and Web app for learning about and managing digital and physical security. From how to send a secure message to dealing with…

Inject DLLs into the explorer process using icons

A font-based deception tool for red teaming, security research, and whatever else.

Quickjack is a point-and-click tool for intuitively producing advanced clickjacking and frame slicing attacks.

Phishing Simulation mainly aims to increase phishing awareness by providing an intuitive tutorial and customized assessment

Practical labs, notes, and reports for CEH v13 modules — covering web hacking, network pentesting, malware analysis, social engineering, and security…

Identify connection of sessions for social engineering attacks.

Automated phishing simulation tool with 30+ login page templates, URL masking, and multiple tunneling options (Ngrok, Cloudflared, Serveo) for…

A lightweight, self-hosted simulation tool for "ClickFix" (ClearFake) social engineering training. Safely simulates clipboard-injection attacks with…

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

CVE-2024-3094 XZ Utils backdoor research - attack surface visualiser, system vulnerability checker, and general Linux CVE assessment tool