
zoshrinkC2
DNS over HTTPS targeted malware (only runs once)

DNS over HTTPS targeted malware (only runs once)

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

RunPE implementation with multiple evasive techniques (2)

Disrupt WAF by abusing SSL/TLS Ciphers

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…

Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign

PoC for a sleep obfuscation technique leveraging waitable timers to evade memory scanners.

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…


Android security insights in full spectrum.

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Translated strings for World Conqueror 4 (RU)

Gallery Vault dump recovery tool with automated discovery, key derivation and automatic media restoration.

Exploit for Oracle Access Manager padding oracle vulnerability (CVE-2018-2879)

Python POC, Exploit for CVE-2026-29000

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security…

Infisical is the open-source platform for secrets, certificates, and privileged access management.

Secure tunneling daemon implementing VPN protocols with TLS encryption, certificate authentication, and routing/firewall configuration for private…