
CVE-2019-0604
CVE-2019-0604: SharePoint RCE detection rules and sample PCAP

CVE-2019-0604: SharePoint RCE detection rules and sample PCAP

Zeek package that detects CVE-2022-22954 exploit attempts, logs exploit URIs and attacker response data to aid in incident response and network…

Critical buffer validation bypass in deserialize_tensor() (llama.cpp < b8492). Null tensor buffer skips bounds check, enabling unauthenticated…

Detailed analysis of Fortinet FortiCloud SSO authentication bypass (CVE-2026-24858) including technical breakdown, attack scenarios, detection…

Exploring CVE-2021-42013, using Suricata and OpenVAS to gather info

https://github.com/corelight/CVE-2021-38647 without the bloat

Repo containing lua scripts and PCAP to find CVE-2020-0601 exploit attempts via network traffic

A framework that create an advanced stealthy dropper that bypass most AVs and have a lot of tricks

Curated collection of cybersecurity research reports covering CVE analysis, exploit research, threat intelligence, and offensive security from…

CVE‑2025‑42957 exposes an RFC‑enabled SAP S/4HANA module that lets low‑privileged users inject ABAP code to create admin accounts and gain full…

My portfolio showcasing vulnerability research (CVE-2026-11989, CVE-2026-11395) and automated threat orchestration engineering (Lucius Engine,…

CVE-2025-23266 targets FastAPI’s parse_request() function, where oversized HTTP headers cause a buffer overflow and remote code execution. The…

Cisco Adaptive Security Appliance Software/Cisco Firepower Threat Defense - Directory Traversal

Walkthrough of detecting, investigating, and responding to a CVE-2024-24919 path traversal attack, including log analysis, threat intel checks, and…

🔍 Just wrapped up an incident report on a Phishing Alert (Event ID 257, SOC282). Enhancing my expertise in email threat detection and response! 🚨…

A PoC to trigger CVE-2023-5217 from the Browser WebCodecs or MediaRecorder interface.

CVE-2022-3328 with CVE-2022-41974 and CVE-2022-41973

Fortinet FortiSandbox 4.4.0-4.4.8 - OS Command Injection via tracer-behavior Endpoint