Translate AiTM and device-code phishing kit observations into draft
Tacklebox atomics + rigs. Hunts named kit families (Tycoon 2FA, Mamba 2FA,
Sneaky 2FA, EvilProxy, FlowerStorm/ODx, ONNX, Greatness, Evilginx,
EvilTokens, Kali365) via OSINT (URLScan, VirusTotal, Hunt.io, etc.) AND
grounds post-auth procedures in tier-1 research (Sekoia, Microsoft TI, Push
Security, SpecterOps, Dirk-Jan Mollema). Produces machine-readable draft
artifacts under intel/kits/<kit-slug>/ for human promotion. Never writes
to atomics/ or rigs/ directly. Use when triaging a suspect AiTM page,
enriching an existing kit family with new procedures, or producing
pipeline-ready intel on post-authentication behavior. Distinct from
infra-malware-delivery-hunter (which hunts masquerading software delivery
infrastructure, not credential harvest).
2026-05-17