This is a novel technique that leverages the well-known Device Code phishing approach. It dynamically initiates the flow when the victim opens the phishing link and instantly redirects them to the authentication page. No authentication method, not even FIDO, is able to protect against this type of attack.
☆205Sep 19, 2025Updated 10 months ago
Alternatives and similar repositories for DeviceCodePhishing
Users that are interested in DeviceCodePhishing are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- OAuth Device Code Phishing Toolkit☆134Apr 18, 2026Updated 3 months ago
- ☆294Aug 14, 2025Updated 11 months ago
- Cobalt Strike BOF for evasive .NET assembly execution☆321Mar 31, 2025Updated last year
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆312Jul 5, 2026Updated 2 weeks ago
- A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office3…☆174Jul 31, 2025Updated 11 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI☆1,350Jun 9, 2026Updated last month
- A fork of the great TokenTactics with support for CAE and token endpoint v2☆434Jul 13, 2026Updated last week
- A tool designed for smuggling interactive command and control traffic through legitimate TURN servers hosted by reputable providers such …☆429Jun 9, 2026Updated last month
- Lateral Movement via Bitlocker DCOM interfaces & COM Hijacking☆444Jun 27, 2025Updated last year
- SOCKS5 proxy tool that uses Azure Storage services as a means of communication.☆359Mar 21, 2026Updated 4 months ago
- Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective☆181May 31, 2026Updated last month
- ☆229Jul 9, 2026Updated last week
- tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it☆135Aug 23, 2025Updated 10 months ago
- Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading …☆167Feb 14, 2026Updated 5 months ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- SACL Scanner is a tool designed to scan and analyze SACLs.☆52Feb 13, 2025Updated last year
- Demo code JavaScript POC that tricks user into sending Windows hash to responder☆37Dec 12, 2025Updated 7 months ago
- Linker for Beacon Object Files☆191Jun 27, 2026Updated 3 weeks ago
- Parses cached certificate templates from a Windows Registry file and displays them in the same style as Certipy does☆96Jul 3, 2025Updated last year
- Azure JWT Token Manipulation Toolset☆736Dec 6, 2024Updated last year
- Automated Evilginx phishlet creator Extension for Burpsuite☆69Jan 10, 2025Updated last year
- BAADTokenBroker is a post-exploitation tool designed to interact with Microsoft Entra ID device-bound keys.☆83Apr 11, 2026Updated 3 months ago
- SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.☆419Sep 26, 2025Updated 9 months ago
- Windows protocol library, including SMB and RPC implementations, among others.☆805Jul 14, 2026Updated last week
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Serverless AITM Simulation Framework for Entra ID and M365☆240Dec 29, 2025Updated 6 months ago
- Abusing Azure services over C2☆377Jan 20, 2026Updated 6 months ago
- One WSL BOF to rule them all☆178Jan 14, 2026Updated 6 months ago
- TokenSmith generates Entra ID access & refresh tokens on offensive engagements. It is suitable for both covert adversary simulations and …☆415Jan 23, 2025Updated last year
- Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data☆410Updated this week
- Ghosting-AMSI☆246Apr 24, 2025Updated last year
- A tool to modify SCCM remote control settings on the client machine, enabling remote control without permission prompts or notifications.…☆121Oct 20, 2024Updated last year
- ☆141Nov 17, 2025Updated 8 months ago
- Azure Post Exploitation Framework☆250Oct 27, 2025Updated 8 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Local SYSTEM auth trigger for relaying - X☆159Jul 23, 2025Updated 11 months ago
- Lnk crafting and research tools☆181Mar 4, 2026Updated 4 months ago
- BOF with Synthetic Stackframe☆258Oct 30, 2025Updated 8 months ago
- BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation☆132Mar 27, 2026Updated 3 months ago
- ↕️🤫 Stealth redirector for your red team operation security☆1,095Updated this week
- Dig your way out of networks like a Meerkat using SSH tunnels via ClickOnce.☆301May 2, 2025Updated last year
- ☆61Jun 2, 2025Updated last year