
OmniSec-Hex
Browser-local security monorepo with six modules for mobile APK/IPA triage, client-side DAST fuzzing, OSINT directories, offline AI threat scoring,…

Browser-local security monorepo with six modules for mobile APK/IPA triage, client-side DAST fuzzing, OSINT directories, offline AI threat scoring,…

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

The PoC of information disclosure in Microsoft Desktop Windows Management.

A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

Talk to your Intel Management Engine directly — zero-dependency Python tool. Finds memory leaks, partition manifest, live MKHI probing. First public…

A OWASP Based Checklist With 80+ Test Cases


My musings with PowerShell

Proof-of-concept exploit and vulnerability disclosure for HiSilicon hi3520d DVR/NVR devices. Demonstrates RCE via web interface, backdoor…

Security profiling for blackbox iOS

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

cldflt.sys information disclosure vulnerability (KB5034765 - KB5035853, Win 11).

Find Electron Apps Vulnerable to CVE-2023-4863 / CVE-2023-5129

Proof-of-concept for CVE-2018-9950, an out-of-bounds read vulnerability in Foxit Reader/PhantomPDF leading to information disclosure and potential…

Proof-of-concept exploit for CVE-2019-1108, an RDP client information disclosure vulnerability that leaks memory contents via specially crafted…

CVE-2026-50416: Windows 11 KASLR bypass

macOS IPC, launchd, Mach-O, and trust relationship explorer — zero-dependency terminal-native forensic tool

iOS Syscall Explorer for IDA 9.X