
DB_Audit_Research
Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

Technical write-up and analysis of PrintNightmare (CVE-2021-1675 / CVE-2021-34527), covering RCE/LPE exploitation, detection via Windows event logs,…

A curated list of AI Security materials and resources for Pentesters, Bug Hunters, and Security Researchers.

Self-referenced local contrast for knowledge-poison detection in retrieval-augmented generation

A curated collection of resources for learning and researching LLM prompt injection attacks, defenses, and security.

The Intelligent Process Lifecycle of Active Cyber Defenders

Paranoid's library contains implementations of checks for well known weaknesses on cryptographic artifacts.

Cisco ASA Software and ASDM Security Research

SSRF (Server Side Request Forgery) testing resources

Cloud, CDN, and marketing services leveraged by cybercriminals and APT groups

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

Curated collection of offensive security conference slide decks covering kernel and mobile exploitation, VM/container escapes, and…

Select Bugs From Binary Where Pattern Like CVE-1337-Days

Demystifying Exploitable Bugs in Smart Contracts

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU


This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

PoC, IOCs, and detection logic for the SharePoint /_trust WS-Federation BinaryFormatter deserialization chain. Lab reconstruction covering…