
violin
Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…
authentication-authorizationexploitationosint+8
73

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Proof-of-concept exploit for CVE-2025-29927, demonstrating Next.js middleware bypass via the x-middleware-subrequest header to circumvent…

Deployable AWS-hosted Active Directory pentest lab with domain controller and vulnerable MSSQL; practice S4U2Self abuse, SQL brute force, and RCE.

Lightweight Java utility for identifying and exploiting Apache Shiro vulnerabilities in penetration testing environments.