This is a novel technique that leverages the well-known Device Code phishing approach. It dynamically initiates the flow when the victim opens the phishing link and instantly redirects them to the authentication page. No authentication method, not even FIDO, is able to protect against this type of attack.
☆207Sep 19, 2025Updated 10 months ago
Alternatives and similar repositories for DeviceCodePhishing
Users that are interested in DeviceCodePhishing are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- OAuth Device Code Phishing Toolkit☆137Apr 18, 2026Updated 3 months ago
- ☆296Aug 14, 2025Updated 11 months ago
- Cobalt Strike BOF for evasive .NET assembly execution☆323Mar 31, 2025Updated last year
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆312Updated this week
- A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office3…☆177Jul 31, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI☆1,369Jun 9, 2026Updated 2 months ago
- A fork of the great TokenTactics with support for CAE and token endpoint v2☆443Updated this week
- A tool designed for smuggling interactive command and control traffic through legitimate TURN servers hosted by reputable providers such …☆432Jun 9, 2026Updated 2 months ago
- Lateral Movement via Bitlocker DCOM interfaces & COM Hijacking☆460Jun 27, 2025Updated last year
- SOCKS5 proxy tool that uses Azure Storage services as a means of communication.☆362Updated this week
- Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective☆183May 31, 2026Updated 2 months ago
- ☆230Jul 9, 2026Updated last month
- tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it☆135Aug 23, 2025Updated 11 months ago
- Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading …☆168Feb 14, 2026Updated 5 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- SACL Scanner is a tool designed to scan and analyze SACLs.☆52Feb 13, 2025Updated last year
- Demo code JavaScript POC that tricks user into sending Windows hash to responder☆37Dec 12, 2025Updated 7 months ago
- Linker for Beacon Object Files☆191Jul 28, 2026Updated 2 weeks ago
- Parses cached certificate templates from a Windows Registry file and displays them in the same style as Certipy does☆96Jul 3, 2025Updated last year
- Azure JWT Token Manipulation Toolset☆737Dec 6, 2024Updated last year
- Automated Evilginx phishlet creator Extension for Burpsuite☆69Jan 10, 2025Updated last year
- BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys.☆83Apr 11, 2026Updated 4 months ago
- SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.☆423Sep 26, 2025Updated 10 months ago
- Windows protocol library, including SMB and RPC implementations, among others.☆822Updated this week
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Abusing Azure services over C2☆380Jan 20, 2026Updated 6 months ago
- Serverless AITM Simulation Framework for Entra ID and M365☆242Dec 29, 2025Updated 7 months ago
- One WSL BOF to rule them all☆189Jan 14, 2026Updated 6 months ago
- TokenSmith generates Entra ID access & refresh tokens on offensive engagements. It is suitable for both covert adversary simulations and …☆417Jan 23, 2025Updated last year
- Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data☆415Jul 15, 2026Updated 3 weeks ago
- Ghosting-AMSI☆249Apr 24, 2025Updated last year
- A tool to modify SCCM remote control settings on the client machine, enabling remote control without permission prompts or notifications.…☆121Oct 20, 2024Updated last year
- ☆141Nov 17, 2025Updated 8 months ago
- Azure Post Exploitation Framework☆248Oct 27, 2025Updated 9 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Local SYSTEM auth trigger for relaying - X☆160Jul 23, 2025Updated last year
- Lnk crafting and research tools☆186Mar 4, 2026Updated 5 months ago
- BOF with Synthetic Stackframe☆258Oct 30, 2025Updated 9 months ago
- ↕️🤫 Stealth redirector for your red team operation security☆1,100Jul 20, 2026Updated 3 weeks ago
- BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation☆135Mar 27, 2026Updated 4 months ago
- Dig your way out of networks like a Meerkat using SSH tunnels via ClickOnce.☆302May 2, 2025Updated last year
- ☆61Jun 2, 2025Updated last year