Proof of concept: using a Cloudflare worker for AITM attacks
☆142Jan 28, 2025Updated last year
Alternatives and similar repositories for AITMWorker
Users that are interested in AITMWorker are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of …☆19Apr 4, 2023Updated 3 years ago
- Azure AiTM Function PoC to phish Entra ID Credentials☆28Nov 21, 2025Updated 8 months ago
- Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs☆599Jun 3, 2025Updated last year
- Slides and Codes used for the workshop Red Team Infrastructure Automation☆193Apr 14, 2024Updated 2 years ago
- Bounces when a fish bites - Evilginx database monitoring with exfiltration automation☆184Jun 9, 2024Updated 2 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- ☆103Oct 27, 2022Updated 3 years ago
- ☆15Sep 26, 2023Updated 2 years ago
- Abusing Azure services over C2☆380Jan 20, 2026Updated 6 months ago
- ClickForClickOnce - Generate configurable clickonce payloads☆98Apr 17, 2026Updated 3 months ago
- Weaponized Browser-in-the-Middle (BitM) for Penetration Testers☆672Apr 2, 2026Updated 4 months ago
- TokenSmith generates Entra ID access & refresh tokens on offensive engagements. It is suitable for both covert adversary simulations and …☆417Jan 23, 2025Updated last year
- Azure Post Exploitation Framework☆248Oct 27, 2025Updated 9 months ago
- Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI☆1,369Jun 9, 2026Updated 2 months ago
- A small example of loading BOFs in Python with pure reflection☆19Jan 26, 2023Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A new approach to Browser In The Browser (BITB) without the use of iframes, allowing the bypass of traditional framebusters implemented b…☆455May 29, 2024Updated 2 years ago
- M365/Azure adversary simulation tool that generates realistic attack telemetry to help blue teams improve their detection and response ca…☆330Oct 12, 2025Updated 9 months ago
- Adaptive DLL hijacking / dynamic export forwarding - EAT preserve☆79Aug 5, 2024Updated 2 years ago
- A collection of various and sundry code snippets that leverage .NET dynamic tradecraft☆145May 18, 2024Updated 2 years ago
- Dump NTDS with golden certificates and UnPAC the hash☆649Mar 20, 2024Updated 2 years ago
- Set of python scripts which perform different ways of command execution via WMI protocol.☆168Jun 29, 2023Updated 3 years ago
- Tool to extract username and password of current user from PanGPA in plaintext☆89Dec 23, 2024Updated last year
- A new AiTM attack framework — based on leveraging service workers — designed to conduct credential phishing campaigns. Thanks to its mini…☆164Aug 5, 2025Updated last year
- Indirect Dynamic Syscall, SSN + Syscall address sorting via Modified TartarusGate approach + Remote Process Injection via APC Early Bird …☆805Jan 26, 2026Updated 6 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse en…☆516Updated this week
- ☆122Nov 21, 2024Updated last year
- Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive an…☆1,160May 13, 2026Updated 2 months ago
- Running .NET from VBA☆147Feb 11, 2023Updated 3 years ago
- A PowerShell script to perform PKINIT authentication with the Windows API from a non domain-joined machine.☆178May 13, 2024Updated 2 years ago
- A tool leveraging Kerberos tickets to get Microsoft 365 access tokens using Seamless SSO☆248Aug 25, 2024Updated last year
- evilginx3 + gophish☆2,022Jun 15, 2024Updated 2 years ago
- ☆570Mar 28, 2024Updated 2 years ago
- ☆52Jun 12, 2026Updated last month
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Cobalt Strike BOF that identifies Attack Surface Reduction (ASR) rules, actions, and exclusion locations☆167Mar 1, 2024Updated 2 years ago
- Spartacus DLL/COM Hijacking Toolkit☆1,084Feb 1, 2024Updated 2 years ago
- A tool to modify SCCM remote control settings on the client machine, enabling remote control without permission prompts or notifications.…☆121Oct 20, 2024Updated last year
- Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling☆1,289Mar 19, 2025Updated last year
- ☆100Sep 1, 2024Updated last year
- A lightweight redirector for Google Cloud Run, enabling domain fronting via Google-owned infrastructure.☆151Nov 12, 2025Updated 8 months ago
- CaptainCredz is a modular and discreet password-spraying tool.☆139Updated this week