This is a novel technique that leverages the well-known Device Code phishing approach. It dynamically initiates the flow when the victim opens the phishing link and instantly redirects them to the authentication page. No authentication method, not even FIDO, is able to protect against this type of attack.
☆209Sep 19, 2025Updated last year
Alternatives and similar repositories for DeviceCodePhishing
Users that are interested in DeviceCodePhishing are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- OAuth Device Code Phishing Toolkit☆140Apr 18, 2026Updated 5 months ago
- ☆297Aug 14, 2025Updated last year
- Cobalt Strike BOF for evasive .NET assembly execution☆326Mar 31, 2025Updated last year
- A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office3…☆180Jul 31, 2025Updated last year
- Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI☆1,397Aug 26, 2026Updated 3 weeks ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆317Aug 31, 2026Updated 2 weeks ago
- Lateral Movement via Bitlocker DCOM interfaces & COM Hijacking☆463Jun 27, 2025Updated last year
- A fork of the great TokenTactics with support for CAE and token endpoint v2☆458Sep 13, 2026Updated last week
- A tool designed for smuggling interactive command and control traffic through legitimate TURN servers hosted by reputable providers such …☆437Jun 9, 2026Updated 3 months ago
- tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it☆135Aug 23, 2025Updated last year
- SOCKS5 proxy tool that uses Azure Storage services as a means of communication.☆364Aug 15, 2026Updated last month
- Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective☆190May 31, 2026Updated 3 months ago
- ☆238Aug 18, 2026Updated last month
- Demo code JavaScript POC that tricks user into sending Windows hash to responder☆37Dec 12, 2025Updated 9 months ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading …☆168Feb 14, 2026Updated 7 months ago
- Parses cached certificate templates from a Windows Registry file and displays them in the same style as Certipy does☆96Jul 3, 2025Updated last year
- Azure JWT Token Manipulation Toolset☆735Dec 6, 2024Updated last year
- SACL Scanner is a tool designed to scan and analyze SACLs.☆53Feb 13, 2025Updated last year
- Linker for Beacon Object Files☆191Updated this week
- Abusing Azure services over C2☆382Jan 20, 2026Updated 8 months ago
- Automated Evilginx phishlet creator Extension for Burpsuite☆68Jan 10, 2025Updated last year
- Windows protocol library, including SMB and RPC implementations, among others.☆833Sep 11, 2026Updated last week
- SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.☆433Sep 26, 2025Updated 11 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Serverless AITM Simulation Framework for Entra ID and M365☆242Dec 29, 2025Updated 8 months ago
- TokenSmith generates Entra ID access & refresh tokens on offensive engagements. It is suitable for both covert adversary simulations and …☆422Jan 23, 2025Updated last year
- A tool to modify SCCM remote control settings on the client machine, enabling remote control without permission prompts or notifications.…☆121Oct 20, 2024Updated last year
- BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys.☆82Apr 11, 2026Updated 5 months ago
- One WSL BOF to rule them all☆189Jan 14, 2026Updated 8 months ago
- Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data☆428Jul 15, 2026Updated 2 months ago
- Azure Post Exploitation Framework☆248Oct 27, 2025Updated 10 months ago
- Ghosting-AMSI☆249Apr 24, 2025Updated last year
- Local SYSTEM auth trigger for relaying - X☆160Jul 23, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- BOF with Synthetic Stackframe☆263Oct 30, 2025Updated 10 months ago
- ☆61Jun 2, 2025Updated last year
- Disconnected RSAT - A method of running Group Policy Manager, Certificate Authority and Certificate Templates MMC snap-ins from non-domai…☆310Mar 28, 2026Updated 5 months ago
- Curated list of public Beacon Object Files(BOFs) build in as submodules for easy cloning☆139Jul 30, 2026Updated last month
- ↕️🤫 Stealth redirector for your red team operation security☆1,108Jul 20, 2026Updated 2 months ago
- ☆141Nov 17, 2025Updated 10 months ago
- Weaponized Browser-in-the-Middle (BitM) for Penetration Testers☆684Apr 2, 2026Updated 5 months ago