
CVE-2026-64638
Technical analysis and defensive mitigation for a WordPress Core pre-auth XSS-to-RCE chain, including sanitizer bypass, DOM clobbering, JSONP abuse,…

Technical analysis and defensive mitigation for a WordPress Core pre-auth XSS-to-RCE chain, including sanitizer bypass, DOM clobbering, JSONP abuse,…

Provides PowerShell and batch scripts to back up, restore, and adjust Access Control Lists (ACLs) mitigating PrintNightmare Print Spooler…

React2Shell(CVE-2025-55182) 취약점 기반 침해 시나리오를 재현하고, Wazuh/Sysmon/Coraza WAF 로그로 침해사고를 분석·대응한 DFIR 프로젝트

Static vulnerability findings tracker with parallel search across 11 CVE databases, EPSS enrichment, CISA KEV badges, coordinated disclosure…

A community‑driven cybersecurity knowledge base with 400+ notes, mind‑maps, and cheat‑sheets – built from first principles. Ideal for students, SOC…

The Intelligent Process Lifecycle of Active Cyber Defenders

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

A Simple Ransomware Vaccine

A DTrace on Windows Reimplementation

🗒️ A [work-in-progress] collection for interview questions for Information Security roles

Rules generated from our investigations.

Parses Apple Unified Logs to extract process, thread, activity, timestamp, and message metadata from logarchives or live macOS systems into JSONL/CSV…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

Detect Tactics, Techniques & Combat Threats

Curated Indicators of Compromise and YARA rules from Zscaler ThreatLabz public reports for threat hunting, malware research, and detection…

Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles

A list of cyber-chef recipes and curated links

Ransomware decryption and script deobfuscation utilities from a threat intelligence team, designed for incident responders and malware analysts.