
log4j-honeypot-flask
Internal network honeypot for detecting if an attacker or insider threat scans your network for log4j CVE-2021-44228

Internal network honeypot for detecting if an attacker or insider threat scans your network for log4j CVE-2021-44228

An ssh honeypot with the XZ backdoor. CVE-2024-3094

Client-side PKI toolbox that decodes X.509, CSR, chain, CRL, PKCS#7 and PKCS#12 artifacts, views ASN.1, converts formats, and generates self-signed…

BPF LSM blocker for CVE-2026-31431 (Copy Fail) — blocks authencesn AF_ALG binds at runtime without rebooting

Working PoCs for three NextGen Connect 4.5.2 vulnerabilities.

Proof-of-concept and research repository for CVE-2024-37054, an unsafe deserialization flaw in MLflow PyFunc model loading that can lead to remote…

Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects…

Proof-of-concept demonstrating CVE-2026-22732, a Spring Security flaw where setIntHeader("Content-Length") drops all security headers, with…

The Whale Sentinel Services

Checks Netdata ndsudo SUID PATH privilege escalation exposure for CVE-2024-32019 and validates patches without weaponized exploitation.

0-day malware detection for binaries, source & scripts (that doesn't suck)

Disabled TLS Certificate Verification for HashiCorp Vault KMS in confluent-kafka


A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

XLL Phishing Tradecraft

IoT and Operational Technology Honeypot

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

First iteration of ML based Feedback WAF