
pared
Lightweight, secure control plane & real-time web dashboard in Crystal for Linux firewalld and NetworkManager host security.

Lightweight, secure control plane & real-time web dashboard in Crystal for Linux firewalld and NetworkManager host security.
Proof-of-concept exploit for CVE-2026-41940, an authentication bypass in cPanel/WHM. Supports custom payloads and verbose logging, compatible with…

Exploit for CVE-2024-47533, a critical authentication bypass in Cobbler XML-RPC API, granting unauthenticated admin access for educational security…

Authentication bypass exploit for CVE-2026-32746 targeting legacy Telnet servers, with defensive guidance and Go-based implementation for authorized…

KcMapper is a security auditing tool for Keycloak. It exports your Keycloak configuration (realms, clients, users, roles, etc.) into a Neo4j graph…

SSH bastion/jump host/jumpserver

Sandboxed runtime for autonomous AI agents with declarative YAML policies enforcing filesystem, network, and process constraints, plus endpoint-bound…

The easiest, and most secure way to access and protect all of your infrastructure.

Single Packet Authorization > Port Knocking

Agentic AI memory with Ebbinghaus forgetting curve decay. +16pp better recall than Mem0 on LoCoMo.

A reverse proxy like nginx, built on pingora, simple and efficient.

Lightweight edge HTTP(S) server and reverse proxy with automatic SSL, Docker/Consul discovery, per-route authentication, rate limiting, and…

SAML v2.0 bindings in Java using JAXB

A lightweight, cryptography-powered, open-source toolkit built to enforce Zero Trust security for infrastructure, applications, and data in the…

Proof-of-concept exploit for OctoberCMS authentication bypass (CVE-2021-32648), demonstrating unauthorized access and providing a working PoC for…

PoC for CVE-2026-27912 - Windows Kerberos Elevation of Privilege (ResetNightmare). Unauthorized password reset via Kerberos flaw. For security…

Local testing environment for Next.js middleware authorization bypass vulnerability (CVE-2025-29927). Demonstrates exploitation via crafted…

Exploit for CVE-2026-8206 targeting unauthenticated account takeover in the Kirki WordPress plugin. Provides a proof-of-concept for security testing…