byt3bl33d3r / UhOh365
A script that can see if an email address is valid in Office365 (user/email enumeration). This does not perform any login attempts, is unthrottled, and is incredibly useful for social engineering assessments to find which emails exist and which don't.
☆30Updated 4 years ago
Alternatives and similar repositories for UhOh365:
Users that are interested in UhOh365 are comparing it to the libraries listed below
- Exchange your privileges for Domain Admin privs by abusing Exchange☆16Updated 5 years ago
- A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow☆98Updated 3 years ago
- SMBMap is a handy SMB enumeration tool☆37Updated 9 months ago
- The Diagon Attack Framework is a Prismatica application containing the Ravenclaw, Gryffindor, and Slytherin remote access tools (RATs).☆52Updated 2 years ago
- Active Directory information dumper via LDAP☆12Updated 5 years ago
- Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensi…☆12Updated 4 years ago
- A collection of data exfiltration scripts for Red Team assessments.☆98Updated 5 years ago
- Empire is a PowerShell and Python 3.x post-exploitation framework.☆17Updated 4 years ago
- Custom pentesting tools☆25Updated 4 years ago
- PowerSploit - A PowerShell Post-Exploitation Framework☆18Updated 5 years ago
- Red Team Tool Kit☆16Updated 6 years ago
- ThreatBox is a standard and controlled Linux based attack platform. I've used a version of this for years. It started as a collection of …☆73Updated 4 months ago
- Tool to transfer credential files from Firefox to your local machine to decrypt offline.☆23Updated 3 years ago
- My Python Cookiecutter project template☆31Updated 2 years ago
- Automatically spin up infra for phishing☆63Updated 5 years ago
- Covenant is a collaborative .NET C2 framework for red teamers.☆41Updated 3 years ago
- Decode Hashcat '$HEX[]' password output from a password list containing a mixture of non-encoded and encoded passwords☆23Updated 6 years ago
- Small python script wrapper for automating hashcat commands☆37Updated 4 years ago
- A simple "ransomware" using powershell☆14Updated 3 years ago
- ☆135Updated last year
- Sp00fer blog post -☆26Updated 2 years ago
- Analyze ARP requests to identify hosts that are communicating with one another.☆18Updated 5 years ago
- Small and highly portable detection tests.☆9Updated 7 months ago
- Wireless Pentesting Device☆20Updated 4 years ago
- This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, …☆17Updated 2 years ago
- credshed - a scalable database for credential leaks. Written in Python, it can easily ingest poorly-formatted files or entire directorie…☆60Updated 3 years ago
- AV/EDR evasion via direct system calls.☆32Updated 4 years ago
- Parses Nessus .nessus files for exploitable vulnerabilities and outputs a report file in format MM-DD-YYYY-nessus.csv☆39Updated last year
- Miscellaneous tools for BloodHound☆18Updated 3 years ago
- ☆52Updated 6 years ago