
exploitgym
ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

Security Bulletins that relate to Netflix Open Source

An inventory of tools and resources about CyberSecurity that aims to help people to find everything related to CyberSecurity.

Multi-engine framework for unpacking and analyzing VM-protected binaries using dynamic taint tracking, symbolic execution, pattern classification,…

Glasses to detect smart-glasses that have cameras. Ray-BANNED

Curated reference for Android forensic artifacts and log paths, with links to CTF writeups, research papers, and mobile device analysis tooling.

Serverless Functions for establishing Reverse Shells to Lambda, Azure Functions, and Google Cloud Functions

The repository that contains the algorithms for generating domain names, dictionaries of malicious domain names. Developed to research the…

Proof of concept for CVE-2022-0778, which triggers an infinite loop in parsing X.509 certificates due to a bug in BN_mod_sqrt

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

RunAsAnyone: PoC and writeup for bypassing the initial patch of CVE-2024-0044, Android run-as any app vulnerability allowing privilege escalation…

Public exploit and research material for CVE-2026-42980, a Windows kernel WMI integer-underflow vulnerability enabling local privilege escalation to…

WebLogic vulnerability exploration from beginner to expert.

PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers.…

Exploits for CVE-2017-6008, a kernel pool buffer overflow leading to privilege escalation.

The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World

Leveraging patch diffing to discover new vulnerabilities

Machine Learning based Intrusion Detection Systems are difficult to evaluate due to a shortage of datasets representing accurately network traffic…