
mquery
YARA malware query accelerator (web frontend)

YARA malware query accelerator (web frontend)

Proof-of-concept and technical analysis of CVE-2023-25813, a SQL injection vulnerability in Sequelize ORM versions prior to 6.19.1, including…

JAW: A Graph-based Security Analysis Framework for Client-side JavaScript

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

Proof of concept with GDB‑assisted exploitation (educational / lab use only)

Exploit tool for CVE-2025-14847, a MongoDB memory disclosure vulnerability, enabling multi-threaded extraction of sensitive data and secrets from…

Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of…

This repo contains my python script version of CVE-2025-14847 (MongoBleed)

Educational case study of the MOVEit Transfer SQL injection breach (CVE-2023-34362) by Cl0p ransomware group, covering attack timeline, exploitation,…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Proof-of-concept exploit for CVE-2025-14847, a MongoDB zlib decompression vulnerability that leaks uninitialized server memory via crafted BSON…

CVE-2025-14847 MongoDB Memory Leak Exploit

Go proof-of-concept exploit for CVE-2025-14847 (MongoBleed), a MongoDB memory disclosure vulnerability. Crafts malformed BSON documents to leak…

Strafer: A tool to detect potential infections in Elasticsearch instances

MongoDB 内存泄露漏洞 (CVE-2025-14847) 检测工具

CVE-2025-14847 (MongoBleed)