
servicenow
Scans ServiceNow instances for widget-simple-list plugin misconfigurations that expose data via the API, supporting single URLs, URL lists,…

Scans ServiceNow instances for widget-simple-list plugin misconfigurations that expose data via the API, supporting single URLs, URL lists,…

Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

Unauthenticated disclosure of internal folder path, client email, and upload policy for FileRise Pro client portals via /api/pro/portals/get.php

Curated SIEM queries and techniques for offensive discovery of Windows privilege escalation, misconfigured ACLs, services, scheduled tasks, and…

Proof-of-concept exploit for CVE-2026-21994, demonstrating unauthenticated admin session forgery via a hardcoded Flask SECRET_KEY and SSH host…

Python scanner for TestRail servers vulnerable to CVE-2021-40875

Proof-of-concept exploit and technical advisory for an unauthenticated member PII disclosure in a WordPress REST API directory plugin, including…

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

Research framework redefining post-exploitation through decision intelligence.

A static + runtime security scanner for MCP (Model Context Protocol) servers

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption

Retrieve AD accounts description and search for password in it

Useful Google Dorks for WebSecurity and Bug Bounty

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

Academic purposes only. Attack against Salesforce lightning with guest privilege.