
domain-protect
Automated detection of vulnerable domain configurations and subdomain takeover risks across cloud environments, with continuous monitoring and…

Automated detection of vulnerable domain configurations and subdomain takeover risks across cloud environments, with continuous monitoring and…

Controlled penetration testing lab demonstrating CVE-2011-2523 exploitation and mitigation techniques.

Full penetration testing workflow: credential brute force, SSH access and privilege escalation (CVE-2021-4034)

Cybersecurity lab demonstrating Apache CVE-2021-41773 path traversal vulnerability with vulnerable server simulation, scanner, and security reporting.

A demo of the CVE-2025-29927 vulnerability for a NebraskaJS lightning talk

Analyze any GitHub repo (URL or local path) → architecture map, verified run commands, risks, and actionable issues - in minutes.

Mitigate CVE-2020-8554 with Policy Controller in Anthos

simple application with a CVE-2022-45688 vulnerability

Public Disclosure

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)



Proof-of-Concept (POC) of a simple firewall in Python designed to mitigate the Spring4Shell (CVE-2022-22965) RCE attack by inspecting and blocking…

Secure-by-default demo lab showing how container hardening (distroless images, non-root, read-only filesystem, runtime-injected secrets) can…

general purpose workaround for the log4j CVE-2021-44228 vulnerability

This powershell script is intended to be used by anyone looking to remediate the Log4j Vulnerability within their environment. It can target multiple…


simple application with a (unreachable!) CVE-2022-45688 vulnerability