
rasputin
Ressources and papers related to my conferences and work on (un)RASPs. These work is in progress, please be patient :) Don't hesitate to contribute /…

Ressources and papers related to my conferences and work on (un)RASPs. These work is in progress, please be patient :) Don't hesitate to contribute /…

Cisco ASA Software and ASDM Security Research

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

Slide decks from my conference presentations



A curated set of NSO Group internal documents, product materials and sworn testimony that entered the public record in WhatsApp Inc. and Meta…

Proof Of Concept for Android. NoFrak is designed to prevent fracking attacks, as described in "Breaking and Fixing Origin-Based Access Control in…

Advisories, proof of concept files and exploits that have been made public by @pedrib.

MAL-003: Groovy Security Bypass and Stored XSS in Apache OfBiz

MAL-007: XML External Entity via Local Registry Entries in WSO2 ESB

MAL-012: Reflected Cross-Site Scripting in Admin Console leading to Remote Code Execution in Payara Server

Huawei P10 VTR-L29C432B151 CVE-2017-8890 exploit research and bootloader-unlock journey

CVE-2026-43499 research port for Galaxy S24 Ultra SM-S928U1 DZF2 (COMPLETED)

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

adaptive agents for dynamic web penetration testing

