MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.
Role in this project:
Security Engineer Contributions:72 commits, 28 PRs, 49 pushes in 2 years 2 months
Contributions summary:Beau primarily contributed to the `MailSniper` project by adding and modifying functions related to email security and penetration testing. Their changes included adding features like password spraying, the ability to search attachments, and integration with Google's API for calendar injections. Moreover, they implemented regular expression search capabilities and modified existing functionalities to enhance the tool's capabilities for identifying potential security vulnerabilities in Microsoft Exchange environments.
e-mailmicrosoft-exchangepenetration-testing
DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAREFUL NOT TO LOCKOUT ACCOUNTS!
Role in this project:
Security Engineer Contributions:21 commits, 13 PRs, 15 pushes in 5 years 3 months
Contributions summary:Beau primarily contributes to a PowerShell-based password spray tool. Their work involves modifying the core functionality of the script, adding features like domain selection, user list customization, and a confirmation prompt for potentially destructive actions. The user has also added fine-grained password policy enumeration to the tool, which enhances its capabilities within a domain environment. Furthermore, the user incorporates measures to mitigate account lockouts and adds various comments to provide better understanding.
powershell