
Security-101
8 Lessons, Kick-start Your Cybersecurity Learning.

8 Lessons, Kick-start Your Cybersecurity Learning.

Cloud, CDN, and marketing services leveraged by cybercriminals and APT groups

This repository provides a practical comparison of breach intelligence, dark web monitoring, and identity exposure services, with a focus on factors…

Technical analysis and proof-of-concept exploit for CVE-2025-59287, a critical RCE in Windows Server Update Services via unsafe deserialization,…

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

In-depth technical analysis of Cisco ISE RCE vulnerabilities, including exploitation techniques, evasion methods, and remediation strategies for…

A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

SSRF (Server Side Request Forgery) testing resources

Comprehensive open-source book on SELinux covering kernel components, userspace libraries, policy toolchain, and policy language. Includes build…

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

Serverless Functions for establishing Reverse Shells to Lambda, Azure Functions, and Google Cloud Functions

Repository for CoSAI Workstream 4, Secure Design Patterns for Agentic Systems

Vendor-neutral OWASP project mapping quantum-era security risks with a Top 10 risk list, mitigation guidance, and threat models for post-quantum…

PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers.…

OWASP Ontology-driven Threat Modelling framework

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

A collection of my public security advisories.

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…