
ejbca-pqc-lab
Pure PQC two-tier PKI hierarchy using ML-DSA-65 (NIST FIPS 204) on EJBCA Community Edition — Root CA + Sub CA with CRL and OCSP

Pure PQC two-tier PKI hierarchy using ML-DSA-65 (NIST FIPS 204) on EJBCA Community Edition — Root CA + Sub CA with CRL and OCSP

Self-Defeating Audits: reproducible lab showing a low-privilege PostgreSQL role reversibly blinding a trigger-based auditor + poisoning attribution…

OWASP Ontology-driven Threat Modelling framework

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

Proof of concept for exploiting the Heartbeat Extension bug detailed in the CVE-2014-0160. 🗝️ 🔓

Implementation of the Google Zero-Knowledge library for Identity Protocols.

Serverless Functions for establishing Reverse Shells to Lambda, Azure Functions, and Google Cloud Functions

Artifacts for the USENIX publication.

Challenge handouts, source code, and solutions for UofTCTF 2025

Proof-of-concept code for beating Google's ZK proof of quantum cryptanalysis

Walkthrough and PoC of File path traversal vulnerability(CVE-2026-36851) for UnPoller 2.33.0

Rule-based CLI tool that grades organizational defenses against MITRE ATT&CK and D3FEND frameworks, detects security gaps, and proposes mitigations.…

VulnAgent-X: A Layered Agentic Framework for Repository-Level Vulnerability Detection

Segmentation Fault-Oriented Programming exploitation technique
