
CVE-2021-1675-PrintNightmare-Analysis
Technical write-up and analysis of PrintNightmare (CVE-2021-1675 / CVE-2021-34527), covering RCE/LPE exploitation, detection via Windows event logs,…

Technical write-up and analysis of PrintNightmare (CVE-2021-1675 / CVE-2021-34527), covering RCE/LPE exploitation, detection via Windows event logs,…

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)

This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need…

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Kvasir: Penetration Test Data Management

CVE-2022-31814 Exploitation Toolkit.


A honeypot for the Log4Shell vulnerability (CVE-2021-44228).

Some tools to help mitigating Apache Log4j 2 CVE-2021-44228

CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)

An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what…


** DISPUTED ** 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the…

End-to-end SOC investigation: CVE-2011-2523 kill chain, multi-source log correlation, incident report — MITRE ATT&CK T1190

Post-Exploitation EVTX Analyzer for BloodHound Mapping

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…