
alter-zero
RAM efficient terminal agent harness for coding, cybersecurity, and automation.

RAM efficient terminal agent harness for coding, cybersecurity, and automation.

Automatic SSTI detection tool with interactive interface

Rust Weaponization for Red Team Engagements.

My experiments in weaponizing Nim (https://nim-lang.org/)

a guard that blocks catastrophic agent actions

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

To reproduce CVE-2021-31630

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

.NET/PowerShell/VBA Offensive Security Obfuscator

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS, ICMP, HTTP Encapsulation, HTTP/Socks Proxies, UDP...)

Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware…

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.

CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).