
TestRail-files.md5-IAC-scanner
Python scanner for TestRail servers vulnerable to CVE-2021-40875

Python scanner for TestRail servers vulnerable to CVE-2021-40875

Collection of Semgrep rules for static code analysis, detecting security vulnerabilities, and enforcing secure coding practices across multiple…

Proof-of-concept exploit and technical advisory for an unauthenticated member PII disclosure in a WordPress REST API directory plugin, including…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…

Retrieve AD accounts description and search for password in it

MDE relies on some of the Audit settings to be enabled

HardeningKitty - Checks and hardens your Windows configuration

Useful Google Dorks for WebSecurity and Bug Bounty

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

Automation to assess the state of your M365 tenant against CISA's baselines

HardeningKitty and Windows Hardening Settings

Scanner: CVE-2025-34291 Langflow Origin Validation Error / CORS Misconfiguration — Python checker (CISA KEV)

Academic purposes only. Attack against Salesforce lightning with guest privilege.

CVE-2026-11961 — UserRegistration: WordPress User Registration <= 5.2.2 Privilege Escalation. Misconfigured Membership Roles → Unauthenticated Admin…

Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive and hardening…

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)