
cfn_nag
Linting tool for CloudFormation templates

Linting tool for CloudFormation templates

Generates SCAP, Ansible, Bash, and CEL security content for compliance evaluation and automated hardening across Linux hosts, containers, and…

Automating the MITM attack on WSUS

A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.

Mogwai Java Management Extensions (JMX) Exploitation Toolkit

Prommetrix can obtain relevant information from the instances of 'Node Exporter' executed by 'Prometheus'.

Detection for CVE-2025-61882 & CVE-2025-61884

Detailed disclosure of an unauthenticated password change vulnerability in ForLogic Qualiex v1 and v3, enabling remote privilege escalation and…

Documentation of CVE-2026-31283: an email bombing vulnerability in Totara LMS's forgot password API due to missing rate limiting, allowing…

This repository holds a target infrastructure you can use for running the nimbostratus tools.


CVE-2021-46075 - A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access…

Secure-by-default demo lab showing how container hardening (distroless images, non-root, read-only filesystem, runtime-injected secrets) can…


Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

PowerShell scripts to apply and restore Microsoft's registry-based workaround for CVE-2022-30190 (Follina) vulnerability, deployable via InTune for…

There is a path injection vulnerability in OpenPLC-v3, which arises from the program not performing any validity checks on the file path parameters…

Documentation of CVE-2025-66838: a rate-limiting vulnerability in ARIS file upload API allowing authenticated remote attackers to cause denial of…