
Agent-Security-Regression-Harness
Executable security regression testing for agentic applications and MCP-integrated systems.

Executable security regression testing for agentic applications and MCP-integrated systems.

Dockerized labs For Web Expert (OSWE) certification. Preparation for coming AWAE Training ...

Educational exploit for CVE-2022-30190 (Follina) demonstrating MSDT remote code execution via malicious Office documents, with detection and…

Python-based simulated firewall to detect and block Spring4Shell (CVE-2022-22965) exploit attempts. This project filters HTTP requests by identifying…

Walkthrough of detecting, investigating, and responding to a CVE-2024-24919 path traversal attack, including log analysis, threat intel checks, and…

Educational demonstration of CVE-2025-42957: an RFC-enabled SAP S/4HANA module vulnerability allowing low-privileged ABAP injection for admin account…

Instructions for rapid deployment of Tomcat v9.0.90 with java 25.0.1 2025-10-21 LTS on Windows Server 2019 Standard for lazy researchers.

Proof-of-concept exploit for CVE-2020-3452 directory traversal vulnerability in Cisco ASA and Firepower Threat Defense appliances. Intended for…

Go-based MITM HTTP/HTTPS proxy for intercepting, inspecting, and replaying traffic. Features admin dashboard, AI copilot, threat scanning, caching,…

Comprehensive PoC and detection toolkit for CVE-2025-5777 (CitrixBleed 2), an out-of-bounds memory read in NetScaler ADC/Gateway. Includes exploit…

A Fullstack Academy Cybersecurity project examining the full cycle of the Follina (CVE-2022-30190) vulnerability, from exploit to detection and…

Official guidance and workarounds for CVE-2022-30190, a remote code execution vulnerability in the Microsoft Support Diagnostic Tool (MSDT)…

A PoC to trigger CVE-2023-5217 from the Browser WebCodecs or MediaRecorder interface.

Research on CrushFTP AS2 authentication bypass allowing unauthenticated admin access. Includes PoC scripts, detection rules, and technical analysis…

Fortinet FortiSandbox 4.4.0-4.4.8 - OS Command Injection via tracer-behavior Endpoint

Python PoC for CVE-2026-8181, a critical authentication bypass in Burst Statistics WordPress plugin. Includes exploit automation, bulk scanning, and…

Docker-based security lab demonstrating Apache Struts2 S2-045 (CVE-2017-5638) exploitation and defense, featuring vulnerable and patched applications…

Cisco Adaptive Security Appliance Software/Cisco Firepower Threat Defense - Directory Traversal