
can-i-take-over-xyz
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

This is a repo which documents real bugs in real software to illustrate trends, learn how to prevent or find them more quickly.

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

Tips on how to write exploit scripts (faster!)

This OSINT Notebook provides an overview of the tools, techniques, and resources that I use for a variety of situations when it comes to performing…

A curated list of awesome OSCP resources

A curated list of Android Security materials and resources For Pentesters and Bug Hunters

The FOFA Library collects usage tips, common scenarios, F&Q, and more for FOFA.

Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs

A list of covert channels and steganography/steganalysis resources (books, papers & tools)

Curated OSINT compilation on Log4Shell (CVE-2021-44228) covering detection methods, attack surface, mitigation steps, and indicators of compromise…

Artefacts for blog post on finding CVE-2025-37899 with o3

Summary of Cyber Security interview questions I have been through, hope this helps

EU focused compliance MCP server

Clickbait. The CVE is AI slop.

A list of edge cases that occur in bug bounty programs, conversations on how they should be handled. The goal is to standardise the way that specific…

These templates are suggestions of how the Obsidian notetaking tool can be used during an OSINT investigation. The example data in those files should…