
Cuteit
IP obfuscator made to make a malicious ip a bit cuter

IP obfuscator made to make a malicious ip a bit cuter

Emulates a Cisco ASA Anyconnect VPN service for credential harvesting and VBS payload delivery in red team phishing operations.

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor…

Modlishka. Reverse Proxy.

Phishing with a fake reCAPTCHA

Spoof emails from any of the +2 Million domains using MailChannels (DEFCON 31 Talk)

Track the GPS location of the user's smartphone or PC and capture a picture of the target, along with IP and device information.

Generates obfuscated IP addresses and URLs using DWORD, octal, hex, IPv6-mapped, and fake-domain @ tricks for penetration testing, phishing…

evilginx3 + gophish

An fully configurable linkedin scrape : scrape anything within linkedin

real time face swap and one-click video deepfake with only a single image

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

HTML/CSS/JS templates for Browser-In-The-Browser phishing attacks, embedding fake login windows with customizable titles, domains, and phishing links…

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

Automates phishing and post-phishing activities with an almost-transparent reverse proxy that dynamically mirrors target web apps and interacts with…


Automates vishing calls via Discord bot and API to intercept SMS one-time passwords, bypassing SMS verification for PayPal, Google, Instagram, and 3D…