

Killer is a super simple tool designed to bypass AV/EDR security tools using various evasive techniques and used by Patchwork group.

ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a system…

my extended take on Mark Brand's CVE 2016-3861 libutils bug

These templates are suggestions of how the Obsidian notetaking tool can be used during an OSINT investigation. The example data in those files should…

Open source Android, iOS and Web app for learning about and managing digital and physical security. From how to send a secure message to dealing with…

A simple python script to exploit CVE-2025-59528, this an Authenticated RCE vulnerability in Flowise application, a popular AI tool. That is also…

Katana Botnet used for DDoS attacks based on the Mirai Botnet. TEACHING PURPOSES ONLY! I CANNOT BE HELD RESPONSIBLE FOR ANYTHING YOU DO WITH IT! I…

This repository will contain many mindmaps for cyber security technologies, methodologies, courses, and certifications in a tree structure to give…

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.

A collection of web pages vulnerable to SQL injection flaws

POC Highlighting Obfuscation Techniques used by FIN threat actors based on cmd.exe's replace functionality and cmd.exe/powershell.exe's stdin command…

CVE-2021-38647 - POC to exploit unauthenticated RCE #OMIGOD

Automated ELF binary analysis tool for CTF/PWN challenges. Extracts security mitigations, ROP gadgets, PLT/GOT tables, and decompiles ASM to C using…

CVE-2026-66804 Windows Cross Device virtual camera EoP - Standard user to SYSTEM

End-to-end simulation of detecting a root-less Android Drop Device (Casper) using Wazuh SIEM to capture Layer 7 attacks like Shellshock…

Complete analysis of CVE-2025-21298, a double free vulnerability related to ole32 library in windows.

Script to obfuscate a payload the same way as it was done by the XZ utils attack (CVE-2024-3094)