
OpenPetya
A Proof-of-Concept bootkit and UEFI boot application inspired by Petya ransomware, written in Assembly, C, and C++

A Proof-of-Concept bootkit and UEFI boot application inspired by Petya ransomware, written in Assembly, C, and C++

Curated list of CVEs that have been reverse-engineered and analyzed, serving as a resource for vulnerability research, exploitation understanding,…

Intentionally vulnerable Golang programs exposing web, gRPC, and database/sql flaws for security training, vulnerability discovery, and remediation…

macOS persistence mechanism scanner with code signature verification and timeline tracking.

AST-level Python obfuscation engine with AES-256 encryption, runtime payload protection, and control-flow flattening for security research and…

Open-source instrumentation framework for Android apps and Java middleware, modifying code during on-device compilation via the ART compiler.…

Another new coercion primitive with LPE - machine-account NTLM coercion from a non-admin user via Windows Store InstallService plugin resolution…

German OWASP Day conference site & presentation archive

CentOS Control Web Panel, Root Privilege Escalation

NotebookLM on steroids — purpose-built for security researchers.

Spring Framework RCE (Quick pentest notes)

Exploit for CVE-2023-4427 targeting Chrome 117 V8, using many cross-origin iframes to brute-force ASLR and achieve code execution. Provides…


Linux kernel exploit for CVE-2020-27786 using userfaultd race condition to trigger use-after-free, leak kernel addresses via msg_msg, and overwrite…

A CodeQL workshop covering CVE-2021-21380

Proof-of-concept exploit for an actively exploited Zimbra Collaboration Suite vulnerability, designed for authorized penetration testing and…

Proof-of-concept for CVE-2026-86218, a pre-auth remote code execution in N-central, intended for authorized security testing and educational research…