
EVTX-ATTACK-SAMPLES
Curated collection of Windows EVTX attack samples mapped to MITRE ATT&CK techniques, designed for testing detection scripts, DFIR training, and…

Curated collection of Windows EVTX attack samples mapped to MITRE ATT&CK techniques, designed for testing detection scripts, DFIR training, and…

Proof-of-concept exploit for CVE-2026-26012, a broken access control in Vaultwarden that allows any organization member to enumerate and decrypt all…

Research pipeline for detecting latent indirect prompt-injection exposure signals in agentic LLMs via hidden-state probing, including trace…

💻🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Curated macOS security and privacy guide with practical instructions for threat modeling, disk encryption, firewall configuration, secure…

Curated collection of LLVM security resources covering binary lifting, code obfuscation, static analysis, symbolic execution, sanitizers, and…

Curated CTF writeup collection for GlacierCTF 2023 covering pwn, rev, web, crypto, and smart contract challenges with solutions and educational…

This is an analysis for CVE-2025-32433 (Erlang OTP SSH Vulnerability). I did not write any of the code, I only wrote comments describing what the…

Cybersecurity writeups, walkthroughs, and technical notes by Nanashi Bx2.

A curated collection of resources for learning and researching LLM prompt injection attacks, defenses, and security.

Curated collection of real-world vendor-ignored vulnerability reports with affected versions, organized by publication date for security researchers…

Exploit writeups I've authored

A collection of awesome security hardening guides, tools and other resources

Collection of KQL queries

A collection of awesome framework, libraries, learning tutorials, videos, webcasts, technical resources and cool stuff about Interview for Security &…

Draw.io libraries for threat modeling diagrams

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…