
javascript-obfuscator
Obfuscates JavaScript and Node.js code with variable renaming, string encryption, control flow flattening, and anti-debugging to protect source code…

Obfuscates JavaScript and Node.js code with variable renaming, string encryption, control flow flattening, and anti-debugging to protect source code…

Python codecs extension featuring CLI tools for encoding/decoding anything

Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.

Proof-of-concept local privilege escalation tool exploiting a kernel XFRM/ESP vulnerability (CVE-2026-43503) via crafted AES-CBC encrypted payloads…

Educational lab replicating the XZ Utils backdoor (CVE-2024-3094) with a custom Ed448 key pair. Includes a patched liblzma, systemd service, and…

Red Team Coin for crypto-mining operations.

Domain-specific language compiler for creating arithmetic circuits targeting the RISC Zero zero-knowledge proof system, enabling custom accelerators…

CVE-2025-14611 CentreStack and Triofox full Poc/Exploit

This is the Heratbleed bug (CVE-2014-0160) documentation I did for Advenced Cyber Attacks course.

A secure, decentralized P2P ephemeral network in C++. Features a custom DHT, encrypted transport, and autonomous NAT traversal using high-performance…

Custom vulnerable VM (Ubuntu 14.04) designed for teaching multi-stage penetration testing. Features 10 interconnected challenges across Forensics,…

notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)

A new simple and powerfull packer for malware

This repo contains : simple shellcode Loader , Encoders (base64 - custom - UUID - IPv4 - MAC), Encryptors (AES), Fileless Loader (Winhttp, socket)

repo showcasing generating "psychic signatures for java" implemented in a nodejs environment 😅

AES-256 encrypted password manager with scrypt/SHA256 key derivation, supporting create, edit, query, and master password change operations with…

Exploitation of a vulnerability in Cisco's node-jose, a JavaScript library created to manage JWT.

Padding oracle exploit for Oracle Access Manager (CVE-2018-2879) enabling decryption of encrypted cookies and encryption of arbitrary plaintext for…