This is a novel technique that leverages the well-known Device Code phishing approach. It dynamically initiates the flow when the victim opens the phishing link and instantly redirects them to the authentication page. No authentication method, not even FIDO, is able to protect against this type of attack.
☆209Sep 19, 2025Updated 11 months ago
Alternatives and similar repositories for DeviceCodePhishing
Users that are interested in DeviceCodePhishing are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- OAuth Device Code Phishing Toolkit☆138Apr 18, 2026Updated 4 months ago
- ☆297Aug 14, 2025Updated last year
- Cobalt Strike BOF for evasive .NET assembly execution☆329Mar 31, 2025Updated last year
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆316Updated this week
- A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office3…☆179Jul 31, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI☆1,388Updated this week
- A fork of the great TokenTactics with support for CAE and token endpoint v2☆450Aug 17, 2026Updated last week
- A tool designed for smuggling interactive command and control traffic through legitimate TURN servers hosted by reputable providers such …☆435Jun 9, 2026Updated 2 months ago
- Lateral Movement via Bitlocker DCOM interfaces & COM Hijacking☆461Jun 27, 2025Updated last year
- SOCKS5 proxy tool that uses Azure Storage services as a means of communication.☆365Aug 15, 2026Updated 2 weeks ago
- Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective☆189May 31, 2026Updated 3 months ago
- ☆232Aug 18, 2026Updated last week
- tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it☆135Aug 23, 2025Updated last year
- Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading …☆169Feb 14, 2026Updated 6 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- SACL Scanner is a tool designed to scan and analyze SACLs.☆53Feb 13, 2025Updated last year
- Demo code JavaScript POC that tricks user into sending Windows hash to responder☆37Dec 12, 2025Updated 8 months ago
- Linker for Beacon Object Files☆191Aug 14, 2026Updated 2 weeks ago
- Parses cached certificate templates from a Windows Registry file and displays them in the same style as Certipy does☆96Jul 3, 2025Updated last year
- Azure JWT Token Manipulation Toolset☆737Dec 6, 2024Updated last year
- Automated Evilginx phishlet creator Extension for Burpsuite☆69Jan 10, 2025Updated last year
- BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys.☆82Apr 11, 2026Updated 4 months ago
- SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.☆431Sep 26, 2025Updated 11 months ago
- Windows protocol library, including SMB and RPC implementations, among others.☆829Aug 18, 2026Updated last week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Abusing Azure services over C2☆381Jan 20, 2026Updated 7 months ago
- Serverless AITM Simulation Framework for Entra ID and M365☆242Dec 29, 2025Updated 8 months ago
- One WSL BOF to rule them all☆190Jan 14, 2026Updated 7 months ago
- TokenSmith generates Entra ID access & refresh tokens on offensive engagements. It is suitable for both covert adversary simulations and …☆420Jan 23, 2025Updated last year
- Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data☆427Jul 15, 2026Updated last month
- Ghosting-AMSI☆251Apr 24, 2025Updated last year
- A tool to modify SCCM remote control settings on the client machine, enabling remote control without permission prompts or notifications.…☆121Oct 20, 2024Updated last year
- ☆142Nov 17, 2025Updated 9 months ago
- Azure Post Exploitation Framework☆248Oct 27, 2025Updated 10 months ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Local SYSTEM auth trigger for relaying - X☆161Jul 23, 2025Updated last year
- Lnk crafting and research tools☆185Mar 4, 2026Updated 5 months ago
- BOF with Synthetic Stackframe☆260Oct 30, 2025Updated 10 months ago
- ↕️🤫 Stealth redirector for your red team operation security☆1,104Jul 20, 2026Updated last month
- BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation☆136Mar 27, 2026Updated 5 months ago
- Dig your way out of networks like a Meerkat using SSH tunnels via ClickOnce.☆303May 2, 2025Updated last year
- ☆61Jun 2, 2025Updated last year