

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

AI coding agents that can't exfiltrate secrets or merge their own PRs.

Open-source AI agent firewall that scans HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, emitting verifiable…

A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the…

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…


CVE-2026-21876 PoC: WAF charset bypass (Flask, ASP.NET and Spring Boot stands)

Reflective PE packer.

PyMultitor - Python Multi Threaded Tor Proxy

Malformed ZIP archive that evades antivirus detection by declaring Method=0 (stored) while containing DEFLATE-compressed payload.

SOCKS5-to-HTTP proxy bridge that tunnels arbitrary TCP streams (SSH, SMTP, TLS) through standard HTTP requests, enabling network traffic obfuscation…

POC code according to trendmicro's research

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.

SSH man-in-the-middle tool

Lab4PurpleSec is a modular Purple Team homelab combining a vulnerable Active Directory environment (GOAD), a Docker-based web DMZ, pfSense +…