
pwnlift
Easy peasy file uploads

Easy peasy file uploads

Default Detections for EDR

Secure, ephemeral secret sharing for developers.

Proof-of-concept exploit for CVE-2026-78122, demonstrating container filesystem and environment variable exfiltration through docker-socket-proxy's…

A privacy and security engineering toolkit: Discover, understand, pseudonymize, anonymize, encrypt and securely share sensitive and personal data:…

FARO - Document Sensitivity Detector

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

Autonomous agent framework with structured memory, safety hooks, and loop management. Built by the agent that runs on it.

An open source swiss army knife for arbitrary communication over application protocols

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

Remote Administration Tool for Android devices

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Python exploit for CVE-2026-3333 demonstrating DNS rebinding to access cloud metadata and steal IAM credentials through an SSRF-vulnerable web app.

PoC exploit for CVE-2026-21015 that abuses PHP filter chains to read arbitrary files through a vulnerable include() call, disclosing source and…

Proof-of-concept exploit for CVE-2026-21004: uses crafted SQLite FTS3/4 MATCH prefix queries as a blind oracle to recover indexed secret data…