
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…
Tools for identifying, assessing, and prioritizing security weaknesses in systems and applications.

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

A static + runtime security scanner for MCP (Model Context Protocol) servers

A defense tool - detect web shells in local directories via md5sum

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

wasm2c sandbox escape. An untrusted WebAssembly module breaks out of the generated C sandbox and executes an arbitrary shell command on the host.

Vulnerability triage with provenance. Resolves CVEs from locally built corpora (NVD/KEV/EPSS, ExploitDB, nmap script.db) and emits verification…

Java RMI security testing tool for detecting, enumerating, and exploiting insecure RMI services using ysoserial deserialization gadgets to achieve…

Research framework redefining post-exploitation through decision intelligence.

Privilege Escalation Enumeration Script for Windows

Local file inclusion exploitation tool

This is a PoC for bypassing UAC using DLL hijacking and abusing the "Trusted Directories" verification.

Ethereum recon and exploitation tool.

The Secure Coding Framework

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

secator - the pentester's swiss knife

Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting…

The StackRox Kubernetes Security Platform performs a risk analysis of the container environment, delivers visibility and runtime alerts, and provides…

Hardening Script for Linux Servers/ Secure LAMP-LEMP Deployer/ CIS Benchmark