
chef-mysql-hardening
This chef cookbook provides security configuration for mysql.

This chef cookbook provides security configuration for mysql.

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to…

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption

Useful Google Dorks for WebSecurity and Bug Bounty


Automating the MITM attack on WSUS

Standalone PoC for unauthenticated RTMP publish in SRS media servers; verifies the vulnerability, supports HTTP API side-channel check, and enables…

Scans exported Azure domain dumps for plaintext passwords, connection strings, storage keys, and other secrets; generates redacted CSV/HTML reports…

Proof-of-concept exploit for OPC UA authentication bypass using None security policy, including a simulated server to demonstrate unauthorized…

Milvus 认证安全检测脚本:CVE-2025-64513 (sourceid后门) / CVE-2026-26190 (/expr弱token) / 内部端口53100

Python PoC for CVE-2026-22007: NTP monlist amplification over IPv6, including a simulated vulnerable server and spoofed UDP reflection attack.

An ADCS honeypot to catch attackers in your internal network.

PoC Modbus TCP exploit demonstrating spoofed writes to read-only coils in simulated PLCs, highlighting SCADA/ICS access control flaws.

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Prommetrix can obtain relevant information from the instances of 'Node Exporter' executed by 'Prometheus'.

Checks for exposed Redis servers