This is a novel technique that leverages the well-known Device Code phishing approach. It dynamically initiates the flow when the victim opens the phishing link and instantly redirects them to the authentication page. No authentication method, not even FIDO, is able to protect against this type of attack.
☆212Sep 19, 2025Updated last year
Alternatives and similar repositories for DeviceCodePhishing
Users that are interested in DeviceCodePhishing are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- OAuth Device Code Phishing Toolkit☆141Apr 18, 2026Updated 5 months ago
- ☆299Aug 14, 2025Updated last year
- Cobalt Strike BOF for evasive .NET assembly execution☆328Mar 31, 2025Updated last year
- A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office3…☆179Jul 31, 2025Updated last year
- Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI☆1,404Aug 26, 2026Updated last month
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆318Aug 31, 2026Updated last month
- Lateral Movement via Bitlocker DCOM interfaces & COM Hijacking☆465Jun 27, 2025Updated last year
- A fork of the great TokenTactics with support for CAE and token endpoint v2☆464Sep 13, 2026Updated 3 weeks ago
- A tool designed for smuggling interactive command and control traffic through legitimate TURN servers hosted by reputable providers such …☆436Jun 9, 2026Updated 4 months ago
- tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it☆135Aug 23, 2025Updated last year
- SOCKS5 proxy tool that uses Azure Storage services as a means of communication.☆365Updated this week
- Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective☆191May 31, 2026Updated 4 months ago
- Demo code JavaScript POC that tricks user into sending Windows hash to responder☆37Dec 12, 2025Updated 9 months ago
- ☆241Sep 21, 2026Updated 2 weeks ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading …☆167Feb 14, 2026Updated 7 months ago
- Parses cached certificate templates from a Windows Registry file and displays them in the same style as Certipy does☆98Jul 3, 2025Updated last year
- Azure JWT Token Manipulation Toolset☆734Dec 6, 2024Updated last year
- SACL Scanner is a tool designed to scan and analyze SACLs.☆53Feb 13, 2025Updated last year
- Linker for Beacon Object Files☆192Sep 16, 2026Updated 3 weeks ago
- Abusing Azure services over C2☆382Jan 20, 2026Updated 8 months ago
- Automated Evilginx phishlet creator Extension for Burpsuite☆68Jan 10, 2025Updated last year
- Windows protocol library, including SMB and RPC implementations, among others.☆839Updated this week
- SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.☆434Sep 26, 2025Updated last year
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Serverless AITM Simulation Framework for Entra ID and M365☆242Dec 29, 2025Updated 9 months ago
- TokenSmith generates Entra ID access & refresh tokens on offensive engagements. It is suitable for both covert adversary simulations and …☆421Jan 23, 2025Updated last year
- A tool to modify SCCM remote control settings on the client machine, enabling remote control without permission prompts or notifications.…☆120Oct 20, 2024Updated last year
- BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys.☆82Apr 11, 2026Updated 5 months ago
- One WSL BOF to rule them all☆189Jan 14, 2026Updated 8 months ago
- Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data☆429Oct 2, 2026Updated last week
- Azure Post Exploitation Framework☆247Oct 27, 2025Updated 11 months ago
- Ghosting-AMSI☆250Apr 24, 2025Updated last year
- Local SYSTEM auth trigger for relaying - X☆160Jul 23, 2025Updated last year
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- BOF with Synthetic Stackframe☆268Oct 30, 2025Updated 11 months ago
- ☆61Jun 2, 2025Updated last year
- Disconnected RSAT - A method of running Group Policy Manager, Certificate Authority and Certificate Templates MMC snap-ins from non-domai…☆312Mar 28, 2026Updated 6 months ago
- Curated list of public Beacon Object Files(BOFs) build in as submodules for easy cloning☆139Jul 30, 2026Updated 2 months ago
- ↕️🤫 Stealth redirector for your red team operation security☆1,116Jul 20, 2026Updated 2 months ago
- ☆140Nov 17, 2025Updated 10 months ago
- Weaponized Browser-in-the-Middle (BitM) for Penetration Testers☆687Sep 18, 2026Updated 3 weeks ago