
RPC-Triage
A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

POC for CVE-2021-1699

POC For CVE-2022-24483

The FreeRDP - Out-of-Bounds Read (CVE-2024-32459) vulnerability concerns FreeRDP, a free implementation of Remote Desktop Protocol. FreeRDP-based…

CVE-2020-25578 and CVE-2020-25579: Some FreeBSD info leak bugs I found in 2020.

cldflt.sys information disclosure vulnerability (KB5034765 - KB5035853, Win 11).

Analyze and demonstrate the local privilege escalation vulnerability (CVE-2025-68921) in Nahimic audio software on gaming laptops, with automated…

Browser-local security monorepo with six modules for mobile APK/IPA triage, client-side DAST fuzzing, OSINT directories, offline AI threat scoring,…

Detect images that likely exploit CVE-2022-44268

Find Electron Apps Vulnerable to CVE-2023-4863 / CVE-2023-5129

Proof-of-concept exploit for CVE-2019-1108, an RDP client information disclosure vulnerability that leaks memory contents via specially crafted…

Integer overflow in Oniguruma

Kernel pointers copied to output user mode buffer with ioctl 0x22A014 in the appid.sys driver.

macOS IPC, launchd, Mach-O, and trust relationship explorer — zero-dependency terminal-native forensic tool

The PoC of information disclosure in Microsoft Desktop Windows Management.

HikCentral Professional - Pre-Auth License ActiveCode Leak

Proof-of-concept exploit for CVE-2022-36163, a format string vulnerability in pdftoroff hovacui 1.1.0 PDF reader, demonstrating local…