

A OSINT project that explores how to dump data from React

A critical mass assignment vulnerability in Camaleon CMS (< 2.9.1) allows authenticated low-privileged users to elevate their privileges to…

Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…

ShowStopper is a tool for helping malware researchers explore and test anti-debug techniques or verify debugger plugins or other solutions that clash…

An automatic obfuscation tool for Android apps that works in a black-box fashion, supports advanced obfuscation features and has a modular…

Open-source tool to bypass windows and linux passwords from bootable usb

PAKURI has been merged with Python and launched as a new project, PAKURI-THON.

NOTICE This repository contains the public FTC SDK for the SKYSTONE (2019-2020) competition season. If you are looking for the current season's FTC…

A project demonstrating an app that is vulnerable to Spring Security authorization bypass CVE-2022-31692

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

A deliberately Next.js app, vulnerable to CVE-2025-29927, Authorization Bypass

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced…


Behavioral eval lab (Quorum) for the superpowers project that drives real coding-agent CLIs (Claude, Codex, Gemini, Kimi, and more) through a QA…

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

Project that brings together several pentest tools

Sample project that uses VEX to supress CVE-2024-29415.