
sloppy-joe
Shields against supply-chain, slopsquatting, and typosquatting attacks from dependencies and code.

Shields against supply-chain, slopsquatting, and typosquatting attacks from dependencies and code.

A tool for retrieving login credentials from Netwave IP cameras using a memory dump vulnerability (CVE-2018-17240)

A powershell poc to load and automatically run Certify and Rubeus from memory.

CVE-2026-0047: Missing permission check in ActivityManagerService.dumpBitmapsProto() — steal UI bitmaps from every running app with zero permissions…

Paper, data and code from Investigating Potential Security Vulnerability Manifestation through Various Analyses & Inferences Regarding Internet RFCs

Archive from the article CVE-2015-5119 Flash ByteArray UaF: A beginner's walkthrough

A PoC to trigger CVE-2023-5217 from the Browser WebCodecs or MediaRecorder interface.

bash CLI trainer — 30 levels from ls to privilege escalation

Rules Shared by the Community from 100 Days of YARA 2023 -

Rules shared by the community from 100 Days of YARA 2026

This tool generates BIP-39 mnemonic phrases derived from Unix timestamps, exploring the 'Milk Sad' vulnerability's implications (CVE-2023-39910)

Escalating privilege in the system from unsigned driver using throttlestop vulnerability

Proof-of-Concept (PoC) exploit for CVE-2019-7139, an unauthenticated SQL injection vulnerability in Magento (PRODSECBUG-2198). For educational and…

793 confusable pairs missing from Unicode TR39, world-first cross-script dataset, font-aware SSIM scoring across 230 fonts and 22,000+ characters

Results and device code from the DEF CON 29 presentation "You're Doing IoT RNG"

Slides and materials from conference presentations

This repository demonstrates a machine learning pipeline for detecting MITRE ATT&CK techniques from logs and enriching the output using a local LLM.