Simulation, Training and Red Team Phishing Framework
-
Updated
Sep 23, 2026 - Go
Simulation, Training and Red Team Phishing Framework
AiTM phishing case study — MFA bypass demonstration (academic red team exercise, ESME Sudria 2025–2026)
Phishing triage analysis of a real Sneaky2FA AiTM campaign targeting Microsoft 365. Documents the full attack chain, IOC extraction, evasion techniques, and sandbox vs reputation tool detection gap.
A controlled lab that reproduces MFA-bypass session hijacking (adversary-in-the-middle and stolen-cookie replay) and the detection layer that catches it. Six context-comparison rules, four Sigma rules, reproducible sample logs. The defence is published, the attack tooling is withheld.
Detection pipeline for AiTM/credential abuse in Azure Identity Protection — identifies axios user agent as a high-confidence IoC, enriches with AbuseIPDB, and automates alerting and response.
Research prototype for detecting AiTM phishing reverse proxies using multi-level heuristic risk scoring
Docker-based AiTM lab for QR login workflows — reverse proxy, browser storage capture, and session replay. Educational use only.
Built a complete Chrome Manifest V3 browser extension that detects Adversary-in-the-Middle (AiTM) reverse proxy phishing attacks in real time. The extension runs 5 detection modules against every page load and produces a 0–100 threat score.
To associate your repository with the aitm topic, visit your repo's landing page and select "manage topics."