The o365-attack-toolkit is a collection of tools and scripts designed to attack and exploit vulnerabilities in Office365. It provides a range of features and functionalities to simulate attacks, test defenses, and identify weaknesses in Office365 environments. The toolkit includes tools for password spraying, password cracking, and token manipulation, as well as scripts for exploiting vulnerabilities in Office365 APIs and services. It also provides features for reconnaissance, enumeration, and data exfiltration. The o365-attack-toolkit is a powerful tool for penetration testers, red teams, and security professionals to test the security of Office365 environments and identify vulnerabilities that need to be addressed.
FEATURES
ALTERNATIVES
Utilizing Alternate Data Streams (ADS) to bypass AppLocker default policies by loading DLL/CPL binaries.
A penetration testing tool for intercepting SSH connections and logging plaintext passwords.
MiniCPS is a framework for Cyber-Physical Systems real-time simulation with support for physical process and control devices simulation, and network emulation.
Very vulnerable ARM/ARM64[AARCH64] application with various levels of vulnerabilities for exploitation training.
A CVE compliant archive of public exploits and corresponding vulnerable software, and a categorized index of Internet search engine queries designed to uncover sensitive information.
Emulates Docker HTTP API with event logging and AWS deployment script.
A blog post about bypassing AppLocker using PowerShell diagnostic scripts
PINNED
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.