
Blue-Team-Notes
You didn't think I'd go and leave the blue team out, right?

You didn't think I'd go and leave the blue team out, right?

Collection of knowledge about information security

RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.

List of Awesome CobaltStrike Resources

Contained is all my reference material for my OSCP / Red Teaming. Designed to be a one stop shop for code, guides, command syntax, and high level…

Project that brings together several pentest tools

Cyberdelia, a Collection of Command and Control frameworks

Metasploit custom modules, plugins, resource script and.. awesome metasploit collection

This repo contains my pentesting template that I have used in PWK and for current assessments. The template has been formatted to be used in Obsidian

Practical Penetration Testing Notes.

Security-research lab: reproduction of CVE-2025-61584 (GHSA-9g7x-737f-5xpc) — command injection via github.head_ref in pull_request_target workflow…

Research lab reproduction of CVE-2026-34243 (GHSA-r4fj-r33x-8v88): command injection via issue_comment.body in .github/workflows/comment.yaml —…

Security-research lab reproducing CVE-2025-53104 (GHSA-432r-9455-7f9x): command injection in discussion-to-slack.yml of gluestack/gluestack-ui

Security-research lab: reproduction of CVE-2025-58371 (GitHub Actions command injection via PR title in Discord PR Notifier), snapshot of…

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are…

Curated collection of offensive security tools and commands for Active Directory attacks, C2, privilege escalation, obfuscation, and web pentesting.

Curated collection of injection payloads for web application security testing, covering SSTI, XXE, XSS, SSRF, SQLi, NoSQLi, LDAP, command injection,…

Security-research lab reproducing CVE-2023-6572 (GHSA-gqvf-3hgp-5hxv): command injection in gradio-app/gradio's workflow_run handling of…