
CVE-2026-39047
Printer exploitation framework for security testing via raw port 9100, featuring PCL payload delivery, DoS bombing, C2 QR codes, phishing QR codes,…

Printer exploitation framework for security testing via raw port 9100, featuring PCL payload delivery, DoS bombing, C2 QR codes, phishing QR codes,…

Deterministic memory-poisoning / prompt-injection measurement axis — CoSnitch (CVE-2026-24301) anchored. Inspect scorer, signed receipts.…

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Security control plane for LLM agents: allowlists, owner kill switch, PIN sessions, rate limits, prompt-injection detection, and output scrubbing to…

Ghostsplice repository: PoC for Cross-Channel Trust Fragmentation Attack

Embed multiple secret messages in LLM chat token choices using arithmetic/Discop steganographic coders, with bit-exact decoding and steganalysis…

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

All the materials for Gareth Heyes' Black Hat talk: CSS: the bomb inside your inbox.

Curated collection of red team and pentest tools grouped by phase: payloads, AMSI bypasses, pivoting, persistence, privesc, credential harvesting,…

USB Army Knife – the ultimate close access tool for penetration testers and red teamers.

Web Based Command Control Framework (C2) #C2 #PostExploitation #CommandControl #RedTeam #C2Framework #PHPC2 #.NETMalware #Malware #PHPMalware #CnC…

Scan LLM outputs and AI-generated content for data exfiltration signals (EchoLeak, CVE-2025-32711) before they reach users or downstream systems

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

Security benchmark for evaluating OpenClaw agents against adversarial execution contexts including poisoned files, injected skills, misleading tool…

A collection of data exfiltration scripts for Red Team assessments.

LlamaStack-RCE: Deterministic Supply Chain Exploitation & Hardening Framework [CVE-2024-50050] Focus on AI Security Research…

Step-by-step penetration testing lab exploiting Samba CVE-2007-2447 on Metasploitable 2 using Metasploit, demonstrating root compromise, credential…