
waf-checker
Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609,…

Spoof file icons and extensions in Windows

Educational evercookie demo showing how browser storage and HTTP cache techniques can persistently re-identify a visitor.

IDS/IPS lab for detecting and preventing Apache ActiveMQ RCE (CVE-2023-46604) using GVM, Nmap, Snort, iptables, and UFW.

Tests your WAF with +160 payloads

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

Scripts for: How to Build a Covert Pentesting Infrastructure Almost Free

CVE‑2025‑55182 Detection

Using IPv6 to Bypass Security

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

Windows x64 kernel mode rootkit process hollowing POC.

Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…