
research
Published security research repository featuring academic papers on domain hijacking, 2FA bypass, and large-scale spoofing techniques, authored by…

Published security research repository featuring academic papers on domain hijacking, 2FA bypass, and large-scale spoofing techniques, authored by…

If you've been grinding through HackTheBox machines, Mailing is one of those boxes that genuinely teaches you something. It's rated Easy, runs on…

LetsDefend SOC336 case study on CVE-2025-21298

A practical chain that starts with an innocuous PDF file and ends up in a reverse shell on an AWS EC2 instance

Technical write-up on CVE-2024-21413 (Moniker Link vulnerability)

We are presented with a security alert indicating the detection of the Follina (CVE-2022-30190) vulnerability. A malicious Word document triggered…

During analysis of the ecodotempo.com.br website, a Stored Cross-Site Scripting (XSS) vulnerability was discovered. This vulnerability allows an…

During the analysis of the website ecodotempo.com.br, a Stored Cross-Site Scripting (XSS) vulnerability was discovered. This vulnerability allows an…

Proof-of-concept demonstrating a Clickjacking vulnerability on the G1 website, with a malicious iframe overlay and social engineering popup for…

This repository shows u some information on this vulnerability, which were found by me.

Curated framework of free OSINT tools and resources for gathering intelligence from public sources, organized by category with structured metadata…

FluxER - The bash script which installs and runs the Fluxion tool inside Termux. The wireless security auditing tool used to perform WPA/WPA2…

Open source platform for cyber security analysts with many features for threat intelligence and detection engineering.

MS Office and Windows HTML RCE (CVE-2023-36884) - PoC and exploit

A lightweight tool designed to stop clickfix attacks by using clipboard formatting with execution surface checks

Instructions for installing a vulnerable version of Exim and its expluatation

Lab write-up analyzing CVE-2024-21413 Outlook Moniker Link exploitation, NetNTLMv2 credential leakage via SMB, detection with YARA/Wireshark, and…

A curated portfolio showcasing my SOC investigations, threat hunting projects, DFIR labs, detection engineering, technical blogs, and cybersecurity…