
DB_Audit_Research
Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

Segmentation Fault-Oriented Programming exploitation technique

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

Curated collection of offensive security conference slide decks covering kernel and mobile exploitation, VM/container escapes, and…

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Comprehensive technical research on CVE-2026-43284 (Dirty Frag), including Linux kernel internals, root cause analysis, patch analysis, detection…

Artifacts for the USENIX publication.

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…


VulnAgent-X: A Layered Agentic Framework for Repository-Level Vulnerability Detection

OWASP Ontology-driven Threat Modelling framework

Proof-of-concept code for beating Google's ZK proof of quantum cryptanalysis

Professional vulnerability assessment report for Helm plugin path traversal risk, including technical analysis, impact, remediation, and mitigation…

PoC reproducer for CVE-2026-55994 (Apache Camel camel-iggy): the consumer copies an Iggy message's user-headers onto the Exchange unfiltered, so an…

Proof of concept for exploiting the Heartbeat Extension bug detailed in the CVE-2014-0160. :old_key: :unlock:

Technical Write-Up on and PoC Exploit for CVE-2020-11519 and CVE-2020-11520

ecurity patch for CVE-2023-26136 in tough-cookie 2.5.0 - Prototype pollution vulnerability fix with backward compatibility