
Awesome-MoAI-Security
Curated reading list and taxonomy of attack and defense research for mobile on-device AI systems, covering adversarial, backdoor, model stealing, and…

Curated reading list and taxonomy of attack and defense research for mobile on-device AI systems, covering adversarial, backdoor, model stealing, and…

Open-source adversary emulation for AI agents and MCP servers.

Simple (relatively) things allowing you to dig a bit deeper than usual.

The poc of CVE-2026-23744

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)



Encrypted C2 and post-exploitation framework for red teams, with modular PowerShell/Python/C#/Go agents, many offensive modules, and easy…

Advanced CVE-2023-44487 HTTP/2 Rapid Reset vulnerability exploitation framework. Features multi-connection concurrent attacks, adaptive rate control,…

Adversary simulation framework for authoring and automating attacker TTPs as repeatable YAML scenarios, helping red and blue teams validate detection…

This is the tool to dump the LSASS process on modern Windows 11

Collection of offensive techniques for attacking Windows environments, with practical methods for exploitation, privilege escalation, and adversarial…

Weaponize DLL hijacking easily. Backdoor any function in any DLL.

Public Repo for Atomic Test Harness


Real-time deepfake toolkit for penetration testing of identity verification and video conferencing systems. Supports face swap, image animation, and…

A POC to disable TamperProtection and other Defender / MDE components