
Detection-Rules
This repository contains validated detection rules for adversary behaviors observed during APT29 simulation. Each rule was tested against the actual…

This repository contains validated detection rules for adversary behaviors observed during APT29 simulation. Each rule was tested against the actual…

A curated portfolio showcasing my SOC investigations, threat hunting projects, DFIR labs, detection engineering, technical blogs, and cybersecurity…

Educational Telegram phishing simulation for cybersecurity training and awareness. Demonstrates credential harvesting via fake login pages in…

Purple team project exploiting CVE-2023-23397 Outlook NTLM leak with phishing delivery, plus Sigma/Wazuh detections mapped to MITRE ATT&CK for the…

OSINT tool researched and designed to hunt down IG handles

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

Documentation of my hands-on lab Moniker Link (CVE-2024-21413) completed on TryHackMe.

A font-based deception tool for red teaming, security research, and whatever else.

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

TryHackMe Moniker Link (CVE-2024-21413) walkthrough: Outlook Protected View bypass leading to NTLMv2 hash capture via a crafted moniker link.

Lab write-up analyzing CVE-2024-21413 Outlook Moniker Link exploitation, NetNTLMv2 credential leakage via SMB, detection with YARA/Wireshark, and…

Open-source interactive security awareness training library with 130+ SCORM exercises covering phishing, vishing, BEC, MFA fatigue, and OWASP AI/LLM…

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

CVE Reproduction: cve-2024-43451-ntlm_hash_disclosure_reproduction

PoC for CVE-2025-55319

Blue-team lab: detecting & mitigating CVE-2025-24054 (Windows NTLM hash disclosure) with Sysmon, Wazuh SIEM, and Group Policy