
RemoteTLSCallbackInjection
Utilizing TLS callbacks to execute a payload without spawning any threads in a remote process

Utilizing TLS callbacks to execute a payload without spawning any threads in a remote process

Private Nginx Rift ASLR lab, exploit chain, and demo recordings


Research on CVE-2025-3052, an Insyde firmware vulnerability that exposes an arbitrary write primitive capable of modifying security-critical pointers.

HiddenSteps — a local-first personal workflow intelligence platform

Hands-on vulnerability management case study: how Wazuh flagged a real SSRF (CVE-2025-68616) in WeasyPrint, and how I reproduced and patched it.

Sudo Local Privilege Escalation CVE-2025-32463 (Best For Cases Where the shell is not stable to spawn a new root shell)

CLI rewrite of the Drupalgeddon2 (CVE-2018-7600) PoC — for authorised testing/education

Lab testing documentation for CVE-2026-31431 (Copy Fail) Linux kernel LPE

Centralized Wazuh SCA Assessment for CVE-2026-42945 on NGINX Servers

CVE-2022-0543 - Redis RCE Vulnerability home lab for Red Teaming, Penetration Testing Training with just one DOCKER

Educational Linux privilege escalation exploit targeting CVE-2016-5195 (Dirty COW) to demonstrate kernel vulnerability exploitation and root access…