
it-sec-toolshell
Marp slide deck detailing CVE-2025-53770, a SharePoint zero-day vulnerability, with modular slides, custom themes, and build scripts for HTML, PDF,…

Marp slide deck detailing CVE-2025-53770, a SharePoint zero-day vulnerability, with modular slides, custom themes, and build scripts for HTML, PDF,…

CodeQL-based analysis of CVE-2025-55182 prototype pollution vulnerability in React Server Components, with exploit POC and static detection queries…

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

A curated knowledge base to build, run and mature a SOC (including CSIRT).

Public exploit and research material for CVE-2026-42980, a Windows kernel WMI integer-underflow vulnerability enabling local privilege escalation to…

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

Coq-based formal verification of a Linux kernel eBPF verifier vulnerability (CVE-2020-8835) with reproducible build environment and proof artifacts.

Critical Vulnerability (9.8) - RecordedFuture Triage dynamic analysis engine can fail to record malicious behavior when samples produce very…

A ConfuserEx2 deobfuscator with support for anti tamper, compressor, constants, control flow, and resource recovery.

Comprehensive open-source book on SELinux covering kernel components, userspace libraries, policy toolchain, and policy language. Includes build…

Open-source declarative language for cyber risk modeling. Build Bayesian risk models like QBER, FAIR Monte Carlo engines, and enterprise risk…

Libsafe - Safety Check Bypass Vulnerability (Proof of Concept Exploit & Time Randomization to Thwart It)

Reproducible lab for CVE-2026-33017, an unauthenticated RCE in Langflow. Includes a Dockerized vulnerable service and a least-harm PoC that…

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

Runtime schema + RTTI extraction tool for Deadlock, CS2, Dota, and others (Source 2). No source2gen required.

Build your own 'AirTags' 🏷 today! Framework for tracking personal Bluetooth devices via Apple's massive Find My network.

Educational proof-of-concept for CVE-2024-4947, a V8 Maglev type confusion, demonstrating a full chain from trigger to arbitrary code execution on a…

CVE-2026-50416: Windows 11 KASLR bypass