
DB_Audit_Research
Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

Retrieve AD accounts description and search for password in it

MDE/MDI Defender setup for Ludus

CVE-2026-60137Temporary Emergency Mitigation for CVE-2026-60137 & CVE-2026-63030 (wp2shell)

A specialized vulnerability scanner designed to detect CVE-2024-38526, the Polyfill.io Supply Chain Attack, helping organizations identify and…

Security hotfix for CVE-2017-8802

Proof-of-Concept (POC) of a simple firewall in Python designed to mitigate the Spring4Shell (CVE-2022-22965) RCE attack by inspecting and blocking…

Fast, configurable HTML sanitization library for preventing XSS and malicious code injection from untrusted user input. Provides a policy-driven API…

Controlled penetration testing lab demonstrating CVE-2011-2523 exploitation and mitigation techniques.

A mitigation for CVE-2021-44228 (log4shell) that works by patching the vulnerability at runtime. (Works with any vulnerable java software, tested…

Workaround for CVE-2020-10663 (vulnerability in json gem)

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

Simple batch script to disable the Microsoft Print Spooler service from system

CVE-2025-55182-scanner with 2 different method

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Code canaries to quickly triage hallucinated ('slop') vulnerability reports

🛡️ Open-source and cloud-native Web Application Firewall (WAF)