
device-activity-tracker
A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak…

A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak…

😱 A curated list of amazingly awesome OSINT

An email spoofing testing tool that aims to bypass SPF/DKIM/DMARC and forge DKIM signatures.🍻

Privacy-first behavioral intelligence framework for multi-platform analysis and sociodynamic research.

MS Office and Windows HTML RCE (CVE-2023-36884) - PoC and exploit

Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes…

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

Proof of Concept for the NTLM Hash Leak via .library-ms CVE-2025-24054 / CVE-2025-24071

A lightweight tool designed to stop clickfix attacks by using clipboard formatting with execution surface checks

OSINT investigation into a suspicious recruitment scheme involving miramedesdecasa

PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script

Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input.

This repository contains validated detection rules for adversary behaviors observed during APT29 simulation. Each rule was tested against the actual…

Fish Live In Trees

Writeup on CVE-2020-28328: SuiteCRM Log File Remote Code Execution plus some bonus Cross-Site Scripting

🧨 CVE-2025-14783: Easy Digital Downloads Account Takeover PoC

Public disclosure for CVE-2025-56526 and CVE-2025-56527 — Stored XSS via unsanitized PDF content rendering and plaintext credential exposure in…