
archerysec
ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

HMAC Implementation Example and Explanation

Ruby templating system for generating JSON and XML APIs, with a fix for CVE-2014-4671. Supports partials, inheritance, and custom nodes for flexible…

Exploit for CVE-2021-30180 targeting Apache Dubbo RPC framework, enabling remote code execution via crafted RPC requests in vulnerable versions.

Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so…

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

Knocker, a knock based access control service for your homelab

Proof of concept of CVE-2025-62727 that can cause denial-of-service in FastAPI (based Starlette <= 0.48.0)

eBPF-based Networking, Security, and Observability

Open-source vulnerability scanner with automated network discovery, CVE-based detection, CVSS scoring, risk dashboards, remote agents via gRPC, and a…


Frida-based runtime API monitor for Android apps that logs invoked APIs, parameters, return values, and call origins across predefined or custom…

A small, auditable, terminating, deterministic micro-policy engine

A web version of the bash scripts wrote for Check Point CVE-2026-50751 and CVE-2026-50752. This uses a local server to scan and make changes using…

Proof-of-concept exploit for CVE-2026-11103 demonstrating GraphQL rate-limit bypass through batching and field aliases; includes vulnerable Node.js…

Vatilon-based IP camera firmwares issue Session-Id tokens without verifying credentials, allowing attackers to obtain sessions and retrieve plaintext…

CVE-2020-9483 OR CVE-2020-13921

Clone of suds 0.4 + suds-0.4-CVE-2013-2217.patch