
SkillSpector
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and…

Offline CVE-2022-1471 lab: SnakeYAML unsafe deserialization to RCE; compares vulnerable 1.x vs fixed 2.x using a harmless local payload.

CVE-2026-66804 Windows Cross Device virtual camera EoP - Standard user to SYSTEM

Host and manage multiple Juice Shop instances for security trainings and Capture The Flags

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

Rewe API reverse engineering in Go

Seal Security example — vulnerable npm app (EJS CVE-2022-29078) remediated to sealed versions; GitHub Actions + Jenkins integration

Contained is all my reference material for my OSCP / Red Teaming. Designed to be a one stop shop for code, guides, command syntax, and high level…

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

This repository will contain many mindmaps for cyber security technologies, methodologies, courses, and certifications in a tree structure to give…

This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles into one…

Seal Security example — vulnerable pip app (PyYAML CVE-2020-14343) remediated to sealed versions; GitHub Actions + Jenkins integration

Seal Security example — vulnerable Maven app (SnakeYAML CVE-2022-1471) remediated to sealed versions; GitHub Actions + Jenkins integration

An OpenFlow sniffer to help network troubleshooting in production networks.

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
