
reconkg
Vulnerability triage with provenance. Resolves CVEs from locally built corpora (NVD/KEV/EPSS, ExploitDB, nmap script.db) and emits verification…

Vulnerability triage with provenance. Resolves CVEs from locally built corpora (NVD/KEV/EPSS, ExploitDB, nmap script.db) and emits verification…

Oracle OID LDAP Server Privileges Management Exploit

Pre-auth PoC for CVE-2026-41089 Netlogon CLDAP stack overflow via UDP/389, triggering LSASS crash/DC reboot. Includes exploit script, root-cause…

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

Python scripts for detecting and exploiting OpenSSL Heartbleed (CVE-2014-0160), leaking sensitive memory contents from vulnerable TLS services.

Scan for and exploit CVE-2024-24919 in Check Point Security Gateways, an unauthenticated arbitrary file read that can expose credentials and lead to…

Scans SSH servers for Terrapin-affected OpenSSH versions by grabbing banners over port 22, enabling quick internal audits, penetration testing, and…

This is an analysis for CVE-2025-32433 (Erlang OTP SSH Vulnerability). I did not write any of the code, I only wrote comments describing what the…

Step-by-step demonstration of BlueKeep CVE-2019-0708 exploitation against Windows Remote Desktop Services, including RCE via crafted RDP packets and…

Android Antivirus which doesn't require root, adb, ca install and cloud with many features and ways to detect more zero-day malware

DShield Sensor Log Collection with ELK

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

CVE-2026-24061's poc : a critical authentication bypass in telnetd leading to RCE as root Affects systems with telnetd versions containing the…

CLI tool to audit Azure security posture, RBAC, NSGs, storage, identity, and encryption

Signatures and IoCs from public Volexity blog posts.

Check for LDAP protections regarding the relay of NTLM authentication

Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged processes to…

A compact guide to network pivoting for penetration testings / CTF challenges.