
ubercookie
Educational evercookie demo showing how browser storage and HTTP cache techniques can persistently re-identify a visitor.

Educational evercookie demo showing how browser storage and HTTP cache techniques can persistently re-identify a visitor.

Scripts for: How to Build a Covert Pentesting Infrastructure Almost Free

A VBA implementation of the RunPE technique or how to bypass application whitelisting.

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs…

BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609,…

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Tests your WAF with +160 payloads

Evilginx Phishing Infrastructure Setup Guide - Securing Evilginx and Gophish Infrastructure, Removing IOCs, Phishing TTPs

Spoof file icons and extensions in Windows

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Using IPv6 to Bypass Security

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…

IDS/IPS lab for detecting and preventing Apache ActiveMQ RCE (CVE-2023-46604) using GVM, Nmap, Snort, iptables, and UFW.

CVE‑2025‑55182 Detection

Windows x64 kernel mode rootkit process hollowing POC.

Proof-of-concept tool demonstrating MITM attack to strip SSL/TLS from MySQL connections, exploiting CVE-2015-3152 for network penetration testing.