
CIS GitLab Benchmark Scanner
Audits GitLab projects against the CIS GitLab Benchmark via read-only API checks, generating JSON reports on compliance and hardening recommendations.

Audits GitLab projects against the CIS GitLab Benchmark via read-only API checks, generating JSON reports on compliance and hardening recommendations.

HardeningKitty - Checks and hardens your Windows configuration

Content hijacking proof-of-concept using Flash, PDF and Silverlight

Pentester-focused Docker registry tool to enumerate and pull images

A collection of tools to enumerate and analyse Windows DACLs

Default signature for Jaeles Scanner

The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…




Full penetration testing workflow: credential brute force, SSH access and privilege escalation (CVE-2021-4034)

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)

Proof-of-Concept (POC) of a simple firewall in Python designed to mitigate the Spring4Shell (CVE-2022-22965) RCE attack by inspecting and blocking…

Secure-by-default demo lab showing how container hardening (distroless images, non-root, read-only filesystem, runtime-injected secrets) can…

A demo of the CVE-2025-29927 vulnerability for a NebraskaJS lightning talk

Controlled penetration testing lab demonstrating CVE-2011-2523 exploitation and mitigation techniques.

simple application with a (unreachable!) CVE-2022-45688 vulnerability