
hacktricks
Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Quickly find differences and similarities in disassembled code

Automated testing to find logic and performance bugs in database systems

Turn any collection of documents into a knowledge graph. Extract entities and relationships via LLM, deduplicate with your approval. Map domains,…

An inventory of tools and resources about CyberSecurity that aims to help people to find everything related to CyberSecurity.

CVE2PoC is a tool that helps penetration testers, bug hunters, and security researchers quickly find public exploits or PoCs related to a CVE ID

Useful access control entries (ACE) on system access control list (SACL) of securable objects to find potential adversarial activity

find dll base addresses without PEB WALK

CSPTPlayground is an open-source playground to find and exploit Client-Side Path Traversal (CSPT).

OPPO Find N2 GhostLock (CVE-2026-43499) exploit adaptation

Lists of affected components and affected apps/vendors by CVE-2021-44228 (aka Log4shell or Log4j RCE). This list is meant as a resource for security…

Take first steps in CodeQL for Python by writing a query to find CVE-2024-32022

Demo showing Claude Opus does not find CVE-2023-0266

Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is…

on this git you can find all information on the CVE-2024-23897

Log4shell - Multi-Toolkit. Find, Fix & Test possible CVE-2021-44228 vulneraries - provides a complete LOG4SHELL test/attack environment on shell

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…