
BL00DYM4RY
Educational trojan simulator for cybersecurity training, simulating phishing attacks with social engineering, system reconnaissance, anti-sandbox…

Educational trojan simulator for cybersecurity training, simulating phishing attacks with social engineering, system reconnaissance, anti-sandbox…

CVE-2024-42009 Proof of Concept

🎩 🤟🏻 [P1-$10,000] Google Chrome, Microsoft Edge and Opera - vulnerability reported by Maciej Pulikowski - System environment variables leak -…

A technical case study and exploitation analysis of the Authentication Bypass vulnerability in TP-Link TL-WR840N firmware (CVE-2018-12633).

A list of tools and material on steganography and information hiding

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

My experiments in weaponizing Nim (https://nim-lang.org/)

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).

CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

Simple Windows and Linux keystroke injection tool that exfiltrates stored WiFi data (SSID and password).

A new lightweight, hybrid routing mesh protocol for packet radios

CloakifyFactory - Data Exfiltration & Infiltration In Plain Sight; Convert any filetype into list of everyday strings, using Text-Based…

Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows…

C# Tool to interact with MS Exchange based on MS docs

An open-source framework for detecting, redacting, masking, and anonymizing sensitive data (PII) across text, images, and structured data. Supports…

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.