
Facad1ng
Open-source URL masking & analysis tool for security research, phishing awareness, and defensive testing. Demonstrates adversary techniques used to…

Open-source URL masking & analysis tool for security research, phishing awareness, and defensive testing. Demonstrates adversary techniques used to…

People tracker on the Internet: OSINT analysis and research tool by Jose Pino

The most complete open-source tool for Twitter intelligence analysis

Practical labs, notes, and reports for CEH v13 modules — covering web hacking, network pentesting, malware analysis, social engineering, and security…

Automated Facebook account security testing tool using Selenium and Mechanize for credential harvesting, graph analysis, and social engineering…

OSINT tool for investigating GitHub profiles: tracks username/name history, maps emails to accounts, clones repos for analysis, finds secondary…

Automates OSINT data collection and analysis for threat intelligence, attack surface mapping, and reconnaissance. Integrates 200+ modules for DNS,…

A geolocation OSINT tool. Offers geolocation information gathering through social networking platforms.

Advanced phishing tool combining OAuth Device Code authentication flow with QR codes to harvest Microsoft authentication tokens via MFA update…

A python server tool based on flask , this tool can phish some Facebook credentials!

Real-time two-factor phishing tool that automates credential harvesting by intercepting credentials from a phishing site and submitting them to the…

Transparent reverse proxy for penetration testing that bypasses 2FA, harvests credentials, and proxies multi-domain TLS traffic without client…

Red team ransomware simulator with custom payload generation, centralized C2 dashboard, and file encryption/decryption for penetration testing.

Automated phishing toolkit with pre-built login page templates and multiple port forwarding options (Ngrok, Serveo) for credential harvesting and…

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

HTML/CSS/JS templates for Browser-In-The-Browser phishing attacks, embedding fake login windows with customizable titles, domains, and phishing links…

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…