
vuln-chm-hijack
Potential malicious code execution via CHM hijacking (CVE-2019-9896)

Potential malicious code execution via CHM hijacking (CVE-2019-9896)

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

TryHackMe Moniker Link (CVE-2024-21413) walkthrough: Outlook Protected View bypass leading to NTLMv2 hash capture via a crafted moniker link.

This repository contains validated detection rules for adversary behaviors observed during APT29 simulation. Each rule was tested against the actual…

camjacking templates

Voice-based detective interrogation game. Mistral Large 3 + Voxtral STT + ElevenLabs TTS. Built for the Mistral Worldwide Hackathon 2026.

A lightweight, self-hosted simulation tool for "ClickFix" (ClearFake) social engineering training. Safely simulates clipboard-injection attacks with…

PoC for CVE-2025-55319

CVE Reproduction: cve-2024-43451-ntlm_hash_disclosure_reproduction

POC_CVE-2026-45185 for nuclei-templates

Educational lab demonstrating CVE-2024-21413 Outlook vulnerability exploitation with Python email exploit tool and Responder for NTLM credential…

Docker-based lab demonstrating CVE-2020-7247 remote code execution in OpenSMTPD 6.6.1p1 with a Python PoC for educational security testing.

Local lab reproducing stored XSS in oRPC's OpenAPI docs generation (CVE-2026-33331), with vulnerable and patched versions for comparison and a…

Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.

Um estudo de caso do CVE-2024-21413. Usado como parâmetro a sala do TryHackMe Moniker Link (CVE-2024-21413). Feito edições com claude code no exploit.

Educational cybersecurity project demonstrating exploitation and mitigation of CVE-2020-25213 (WordPress File Manager Plugin RCE). Includes malware…

Educational lab demonstrating CVE-2024-21413 exploitation in Outlook to leak NTLM hashes via malicious UNC links, with custom SMTP/POP3…