
CVE-2025-50154
PowerShell toolkit to audit, harden, and hunt for insecure NTLM/SMB usage, addressing CVE-2025-50154 credential leak risks with event log analysis…

PowerShell toolkit to audit, harden, and hunt for insecure NTLM/SMB usage, addressing CVE-2025-50154 credential leak risks with event log analysis…

Research on CrushFTP AS2 authentication bypass allowing unauthenticated admin access. Includes PoC scripts, detection rules, and technical analysis…

Detects NTLM authentication status by checking LmCompatibilityLevel registry value to assess exposure to CVE-2024-43451 and mitigate credential relay…

Shell script that monitors for a vulnerable sudo process and triggers authentication lockout to mitigate CVE-2021-3156.

Audit and incident response tool for CVE-2026-41940 vulnerability

Detailed analysis of Fortinet FortiCloud SSO authentication bypass (CVE-2026-24858) including technical breakdown, attack scenarios, detection…



A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.

Semantic Observability for UNIX Systems - A lightweight C-based system prober with AI-powered analysis

Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response


BitLocker TPM+PIN Hardening Against CVE-2026-45585 (YellowKey)

CVE-2026-41940 cPanel/WHM auth bypass IOC scanner — fixes false positives in upstream detection script, adds log cross-correlation

Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database

Distributed alerting for the masses!

Multi-host UFW firewall dashboard — explains rules in plain English, detects security gaps, and provides connection diagnostics

A secure low code deception runtime framework, leveraging AI for System Virtualization.