
Zero-Click-RCE-Incident-Response-CVE-2025-21298
Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware…

Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware…

CVE-2022-1292 OpenSSL c_rehash Vulnerability

SSHD Based implant supporting tunneling mecanisms to reach the C2 (DNS, ICMP, HTTP Encapsulation, HTTP/Socks Proxies, UDP...)

Rust Weaponization for Red Team Engagements.

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

To reproduce CVE-2021-31630

Automatic SSTI detection tool with interactive interface

Details about the Blind RCE issue(SPX-GC) in SPX-GC

.NET/PowerShell/VBA Offensive Security Obfuscator

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

CImg Library v.2.3.3 - command injection

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

CVE-2020–14882、CVE-2020–14883

CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

CVE-2025-53652: Jenkins Git Parameter Analysis