
DB_Audit_Research
Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption

Retrieve AD accounts description and search for password in it

MDE relies on some of the Audit settings to be enabled

Burp Suite Extension useful to verify OAUTHv2 and OpenID security


My cheatsheet notes to pentest AWS infrastructure

Automation to assess the state of your M365 tenant against CISA's baselines

Repository contains psexec, which will help to exploit the forgotten pipe

CVE-2026-11961 — UserRegistration: WordPress User Registration <= 5.2.2 Privilege Escalation. Misconfigured Membership Roles → Unauthenticated Admin…

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)


A New Approach to Directory Bruteforce with WaybackLister v1.0

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting)…

Subdomain takeover vulnerability checker

Automating the MITM attack on WSUS