OAuth Device Code Phishing Toolkit
☆140Apr 18, 2026Updated 5 months ago
Alternatives and similar repositories for squarephish2
Users that are interested in squarephish2 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- This is a novel technique that leverages the well-known Device Code phishing approach. It dynamically initiates the flow when the victim …☆210Sep 19, 2025Updated last year
- Terms of Use Conditional Access M365 Evilginx Phishlet☆46Jun 23, 2025Updated last year
- A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office3…☆180Jul 31, 2025Updated last year
- An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard histor…☆117Apr 16, 2026Updated 5 months ago
- Cross Compatible Command and Control☆49Dec 18, 2025Updated 9 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Parser and reconciliation tooling for large Active Directory environments.☆33Feb 18, 2025Updated last year
- ☆239Updated this week
- An HTA Application which builds Azure (Entra) Scenarios for Red Team Simulations☆63Aug 18, 2025Updated last year
- Rust implementation of phantom persistence technique documented in https://blog.phantomsec.tools/phantom-persistence☆67Jun 23, 2025Updated last year
- AzDevRecon is a powerful web-based enumeration tool for offensive security professionals, red teamers, and pentesters targeting Azure Dev…☆32Oct 13, 2025Updated 11 months ago
- ☆80Jan 1, 2026Updated 8 months ago
- Lateral Movement Bof with MSI ODBC Driver Install☆174Sep 30, 2025Updated 11 months ago
- Updated o365 Evilginx phishlet for WHfB☆97Mar 16, 2024Updated 2 years ago
- ↕️🤫 Stealth redirector for your red team operation security☆1,109Jul 20, 2026Updated 2 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it☆135Aug 23, 2025Updated last year
- ☆300Aug 14, 2025Updated last year
- ☆150Sep 9, 2025Updated last year
- A Rust PoC implementation of the Early Bird process hollowing technique, inspired by https://github.com/boku7/HOLLOW.☆31Feb 7, 2025Updated last year
- A Payload Analysis Framework☆124Oct 9, 2025Updated 11 months ago
- Vulnerable (on purpose) programs to leak NtReadVirtualMemory address for stealthier API resolution (no GetProcAddress, GetModuleHandle or…☆42Dec 22, 2025Updated 9 months ago
- Demo code JavaScript POC that tricks user into sending Windows hash to responder☆37Dec 12, 2025Updated 9 months ago
- Weaponizing DCOM for NTLM Authentication Coercions☆215Nov 4, 2025Updated 10 months ago
- The dragon in the dark. A red team post exploitation framework for testing security controls during red team assessments.☆509Mar 15, 2026Updated 6 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Persist like a Dodder☆69May 19, 2025Updated last year
- ☆166May 5, 2025Updated last year
- ☆27Dec 21, 2025Updated 9 months ago
- Python based GUI for browsing LDAP☆184Jul 30, 2026Updated last month
- BadExclusions is a tool to identify folder custom or undocumented exclusions on AV/EDR☆21Feb 8, 2024Updated 2 years ago
- Golang Automation Framework for Cobalt Strike using the Rest API☆59Apr 10, 2026Updated 5 months ago
- Beacon Object File (BOF) to obtain Entra tokens via authcode flow.☆140Jan 17, 2026Updated 8 months ago
- TokenSmith generates Entra ID access & refresh tokens on offensive engagements. It is suitable for both covert adversary simulations and …☆422Jan 23, 2025Updated last year
- Fritter is a heavily modified fork of TheWover and Odzhan's Donut shellcode generator.☆253Aug 4, 2026Updated last month
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- A small How-To on creating your own weaponized WSL file☆128Jul 23, 2025Updated last year
- Vectored Exception Handling Squared☆33Dec 27, 2025Updated 9 months ago
- Lateral Movement as loggedon User via Speech Named Pipe COM & ISpeechNamedPipe + COM Hijacking☆150Jul 2, 2025Updated last year
- Create Entra Global Admin accounts from On-Prem☆25Jul 28, 2025Updated last year
- Zero dependency browser extension for handling import of cookies, Microsoft 365 OAuth tokens, and Graph API interactions.☆39Jun 5, 2026Updated 3 months ago
- Usermode detector that catches indirect syscalls. Traps Hell's Hall, Tartarus' Gate, RecycledGate, and VEH syscalls & Many more.☆90Jun 15, 2026Updated 3 months ago
- SCEP request tool for AD CS and Intune☆77Oct 24, 2025Updated 11 months ago