
CVE-2020-11019
In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TRACE", a possible crash of application could occur due to a read of an…

In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TRACE", a possible crash of application could occur due to a read of an…

Docker-compose to set up a test environment for exploiting CVE-2015-8562

A collection of scripts to help set the appropriate registry keys for CVE-2021-34527

Open .eml test set for evaluating how email security controls and AI mailbox assistants handle indirect prompt injection across disclosure,…

UNIX-like reverse engineering framework and command-line toolset

GEF (GDB Enhanced Features) - a modern experience for GDB with advanced debugging capabilities for exploit devs & reverse engineers on Linux

A fully functional DanderSpritz lab in 2 commands

Win32 and Kernel abusing techniques for pentesters


A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)


A cheatsheet for exploiting server-side SVG processors.

Simple Windows and Linux keystroke injection tool that exfiltrates stored WiFi data (SSID and password).

Proof-of-concept for CVE-2023-4863, a heap buffer overflow in WebP image decoding. Demonstrates the code_lengths trigger mechanism discovered by…

Intentionally vulnerable Golang programs exposing web, gRPC, and database/sql flaws for security training, vulnerability discovery, and remediation…

Efficient Deobfuscation of Linear Mixed Boolean-Arithmetic Expressions

Blue Team detection lab created with Terraform and Ansible in Azure.

Tools and technical write-ups describing attacking techniques that rely on concealing code execution on Windows