
CVE-2024-37054
Proof-of-concept that poisons MLflow registered models via the REST API, embedding a malicious pickle to trigger RCE when the model is loaded.

Proof-of-concept that poisons MLflow registered models via the REST API, embedding a malicious pickle to trigger RCE when the model is loaded.

A machine learning tool that ranks strings based on their relevance for malware analysis.

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

ML-based detection of Zombie ZIP archive header evasion attacks (CVE-2026-0866)

This repository provides the official implementation of POISONCRAFT: Practical Poisoning of Retrieval-Augmented Generation for Large Language Models.

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

Memory-free continual learning framework for malware classification using mode connectivity-based interpolation. Supports class-incremental and…

Graph-based threat detection system using inexact graph vector matching to compare threat graphs with CTI-derived attack query graphs for automated…

Security Scanner for Agent Skills

The repository that contains the algorithms for generating domain names, dictionaries of malicious domain names. Developed to research the…

This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles into one…

Proof-of-concept exploit for CVE-2025-32434, a pickle deserialization vulnerability in PyTorch's weights_only mode, demonstrating malicious tar file…

takes shellcode bad-bytes and banishes them, returning cleaned shellcode with preserved functionalities

image scaling attacks for multi-modal prompt injection

CERTITUDE - A python package to classify URLs as malicious or benign


DGA Domain Detection using Bigram Frequency Analysis

Static analysis of malicious Python code