
Threat_Model_Examples
A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…

Turn any web app into an API. Chrome extension captures browser traffic, auto-generates schemas, lets AI replay APIs directly. No official API needed.

Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in their…

Open-source framework for embedding realistic decoy routes and honey fields into APIs to detect attackers probing business logic, converting…

One missing function call on the route registration was enough to turn the MCP interface into an unauthenticated RCE gateway.

Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

"Reverse engineering analysis of a fileless Remcos RAT variant that injects into svchost.exe via Native API calls. Covers obfuscated payload…

Fork of laravel/framework 10.50.2 with CVE-2026-48019 (CRLF injection in default email rule) backported into ValidatesAttributes::validateEmail.…

This skill helps Claude write secure code and prevent common vulnerabilities.

CVE-2026-39154, Stored XSS in CometChat JS SDK