OAuth Device Code Phishing Toolkit
☆137Apr 18, 2026Updated 4 months ago
Alternatives and similar repositories for squarephish2
Users that are interested in squarephish2 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- This is a novel technique that leverages the well-known Device Code phishing approach. It dynamically initiates the flow when the victim …☆208Sep 19, 2025Updated 10 months ago
- Terms of Use Conditional Access M365 Evilginx Phishlet☆46Jun 23, 2025Updated last year
- An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard histor…☆117Apr 16, 2026Updated 4 months ago
- A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office3…☆177Jul 31, 2025Updated last year
- Cross Compatible Command and Control☆48Dec 18, 2025Updated 8 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- ☆231Updated this week
- Parser and reconciliation tooling for large Active Directory environments.☆33Feb 18, 2025Updated last year
- An HTA Application which builds Azure (Entra) Scenarios for Red Team Simulations☆63Aug 18, 2025Updated last year
- ☆79Jan 1, 2026Updated 7 months ago
- Rust implementation of phantom persistence technique documented in https://blog.phantomsec.tools/phantom-persistence☆64Jun 23, 2025Updated last year
- AzDevRecon is a powerful web-based enumeration tool for offensive security professionals, red teamers, and pentesters targeting Azure Dev…☆31Oct 13, 2025Updated 10 months ago
- Lateral Movement Bof with MSI ODBC Driver Install☆174Sep 30, 2025Updated 10 months ago
- Updated o365 Evilginx phishlet for WHfB☆96Mar 16, 2024Updated 2 years ago
- ↕️🤫 Stealth redirector for your red team operation security☆1,100Jul 20, 2026Updated 3 weeks ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- A Payload Analysis Framework☆123Oct 9, 2025Updated 10 months ago
- tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it☆135Aug 23, 2025Updated 11 months ago
- ☆297Aug 14, 2025Updated last year
- ☆149Sep 9, 2025Updated 11 months ago
- A Rust PoC implementation of the Early Bird process hollowing technique, inspired by https://github.com/boku7/HOLLOW.☆31Feb 7, 2025Updated last year
- Robust Cobalt Strike shellcode loader with multiple advanced evasion features☆206Apr 21, 2025Updated last year
- ☆165May 5, 2025Updated last year
- Golang Automation Framework for Cobalt Strike using the Rest API☆60Apr 10, 2026Updated 4 months ago
- Vulnerable (on purpose) programs to leak NtReadVirtualMemory address for stealthier API resolution (no GetProcAddress, GetModuleHandle or…☆42Dec 22, 2025Updated 7 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Zero dependency browser extension for handling import of cookies, Microsoft 365 OAuth tokens, and Graph API interactions.☆35Jun 5, 2026Updated 2 months ago
- The dragon in the dark. A red team post exploitation framework for testing security controls during red team assessments.☆511Mar 15, 2026Updated 5 months ago
- Demo code JavaScript POC that tricks user into sending Windows hash to responder☆37Dec 12, 2025Updated 8 months ago
- Python based GUI for browsing LDAP☆184Jul 30, 2026Updated 2 weeks ago
- Weaponizing DCOM for NTLM Authentication Coercions☆215Nov 4, 2025Updated 9 months ago
- Persist like a Dodder☆69May 19, 2025Updated last year
- Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.☆88Jun 15, 2026Updated 2 months ago
- Beacon Object File (BOF) for Windows Session Hijacking via IHxHelpPaneServer COM☆71Dec 25, 2025Updated 7 months ago
- Fritter is a heavily modified fork of TheWover and Odzhan's Donut shellcode generator.☆249Aug 4, 2026Updated 2 weeks ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- TokenSmith generates Entra ID access & refresh tokens on offensive engagements. It is suitable for both covert adversary simulations and …☆420Jan 23, 2025Updated last year
- ☆26Dec 21, 2025Updated 7 months ago
- BadExclusions is a tool to identify folder custom or undocumented exclusions on AV/EDR☆21Feb 8, 2024Updated 2 years ago
- Beacon Object File (BOF) to obtain Entra tokens via authcode flow.☆140Jan 17, 2026Updated 7 months ago
- Phantom is project created to perform loading and executing unmanaged code in memory within an IIS environment running in full‑trust mode…☆108Jun 5, 2026Updated 2 months ago
- A small How-To on creating your own weaponized WSL file☆128Jul 23, 2025Updated last year
- Permanently disable EDRs as local admin☆128Dec 19, 2025Updated 7 months ago