
WiFi-Pineapple-MK7_Evil-Portal
Rogue access point toolkit for WiFi penetration testing, deploying evil portal phishing payloads to capture credentials and perform social…

Rogue access point toolkit for WiFi penetration testing, deploying evil portal phishing payloads to capture credentials and perform social…

A Phishing Dropper designed to Pentest.

an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

XLL Phishing Tradecraft

SocialPwned is an OSINT tool that allows to get the emails, from a target, published in social networks such as Instagram, Linkedin and Twitter to…

OSINT Tool: Generate username lists for companies on LinkedIn

Osint tool based on namechk.com for checking usernames on more than 100 websites, forums and social networks.

🕵️♂️ Collect a dossier on a person by username from 6K websites

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

A geolocation OSINT tool. Offers geolocation information gathering through social networking platforms.

Lockphish it's the first tool (07/04/2020) for phishing attacks on the lock screen, designed to grab Windows credentials, Android PIN and iPhone…

Open-source interactive security awareness training library with 130+ SCORM exercises covering phishing, vishing, BEC, MFA fatigue, and OWASP AI/LLM…

Demonstrates capturing NTLM hashes via Responder and executing phishing emails exploiting CVE-2024-21413 to compromise systems.


A command-line tool for reconnaissance and targeted write operations on Confluence and Jira instances.
