
O365-Doppelganger
A quick handy script to harvest credentials off of a user during a Red Team and get execution of a file from the user

A quick handy script to harvest credentials off of a user during a Red Team and get execution of a file from the user

Powerful framework for rogue access point attack.

Automated WPA/WPA2 phishing tool that captures handshakes, spawns a rogue access point, and lures users to a captive portal to harvest credentials…

Ruby on Rails Phishing Framework

Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading a C# port of…

GitBackdorizer (bad name, I know!) Is a proof of concept from Ulisses Castro's talk - 50 ton of backdoors…

Rogue access point toolkit for WiFi penetration testing, deploying evil portal phishing payloads to capture credentials and perform social…

A selfbot for discord made using Discord.py. It comes with 70+ commands and server nuking features

Creates Fake Auth prompt to capture users plaintext passwords

Proof-of-concept exploit for CVE-2018-13257 demonstrating CAS host header spoofing in Blackboard Learn to hijack user sessions via a malicious…

trojan CVE-2024-28085 CVE 28085

Powershell script to create malicious SMB or WebDAV links to steal NTLM authentication

Case Study: SSHtranger Things (CVE-2019-6111, CVE-2019-6110) in Cisco SD-WAN

Real-time deepfake toolkit for penetration testing of identity verification and video conferencing systems. Supports face swap, image animation, and…

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

Curated OSINT cheat sheet with tools, datasets, wiki, and tips for reconnaissance, social media intelligence, and red team operations. Includes…