
EntraTrace
Defensive research tool that documents observable API endpoints and user agents of offensive tooling targeting Microsoft Entra ID, supporting…

Defensive research tool that documents observable API endpoints and user agents of offensive tooling targeting Microsoft Entra ID, supporting…

Penetration tests guide based on OWASP including test cases, resources and examples.

Emulates NIST SP 800-73 PIV smart cards on Windows using a PFX certificate and private key, enabling smart-card authentication for RDP, Citrix, and…

Bulk scanner and mass exploitation tool for CVE-2026-41940 on cPanel/WHM, built for automated target validation and high-speed multi-threaded…

Caches JWT authentication tokens from an auth URL and attaches them as headers to in-scope requests in Burp Suite for automated session handling.

elabFTW < 4.1.0 - account lockout bypass and login brute force

Security advisory detailing a critical authentication vulnerability (CVE-2025-4162029) in Copilot, enabling unauthorized account access via user ID…

Security advisory detailing a critical authentication vulnerability (CVE-2025-4162025) in Copilot, including impact analysis, affected versions, and…

Security advisory detailing a critical authentication vulnerability (CVE-2025-4162028) in Copilot, enabling unauthorized account access via user ID…

Security advisory detailing a critical authentication vulnerability (CVE-2025-4162026) in Copilot, enabling unauthorized account access via user ID…

Security advisory detailing a critical authentication vulnerability in Copilot where user IDs are switched, enabling unauthorized account access and…

Analysis of a logic vulnerability in the macOS SSH client leading to client passphrase exposure to a local attacker

CVE-2026-20182 PoC - Cisco Catalyst SD-WAN Controller / Manager Authentication Bypass (CVSS 10.0)

Low and slow password spraying tool, designed to spray on an interval over a long period of time

Research on Next.js middleware vulnerability (CVE-2025-29927) allowing authorization bypass and potential exploits.

APOLOGEE is a Python script and Metasploit module that enumerates a hidden directory on Siemens APOGEE PXC BACnet Automation Controllers (all…

Enumerate usernames on a domain where you have no creds by using SMB Relay with low priv.

CentOS Control Web Panel, Root Privilege Escalation