
sliver
Adversary Emulation Framework

Adversary Emulation Framework

Research code implementing T-Backdoor, temporal-trigger backdoor attacks on spiking neural networks using rate, latency, and jitter triggers without…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Self-referenced local contrast for knowledge-poison detection in retrieval-augmented generation

CVE-2026-6765, Test only FormAutofill handlers exposed in Firefox

Spawns macOS programs through launchd's private XPC interface without execing them, making EDR record launchd as parent. Supports one-shot,…

Ghostsplice repository: PoC for Cross-Channel Trust Fragmentation Attack

Python proof-of-concept demonstrating IPFS CID spoofing via multihash length extension, highlighting content-addressing verification flaws that can…

Python PoC for CVE-2026-22007: NTP monlist amplification over IPv6, including a simulated vulnerable server and spoofed UDP reflection attack.

CVE-2026-7070 PoC for RDP clipboard hijacking via virtual channel injection; includes simulated server and exploit script for data theft/credential…

Browser PoC demonstrating CVE-2026-2828, a WebGPU timing side-channel that leaks cross-origin iframe pixel values by measuring GPU timestamp-query…

Security benchmark for evaluating OpenClaw agents against adversarial execution contexts including poisoned files, injected skills, misleading tool…

MAAD Attack Framework - An attack tool for simple, fast & effective security testing of M365 & Entra ID (Azure AD).

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

Python3 utility for creating zip files that smuggle additional data for later extraction

Covert data exfiltration via DNS