
SkillsGuard
Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

Exploit and detect CVE-2026-31431 vulnerabilities using a static binary that monitors system integrity and bypasses PAM authentication.

Load/Inject .NET assemblies by; reusing the host (spawnto) process loaded CLR AppDomainManager, Stomping Loader/.NET assembly PE DOS headers,…

RustyWater represents the main payload and the backbone of the entire adversarial operation in Static Kitten group attacks.

VMWare Aria Operations for Networks (vRealize Network Insight) Static SSH key RCE (CVE-2023-34039)

Mind-Maps of Several Things

Rust Weaponization for Red Team Engagements.

Exploiting CVE-2022-0847 - written by : Antonius (w1sdom)

CVE-2023-34039

Proof-of-concept exploit demonstrating UMCI bypass in Internet Explorer using JScript and ActiveX to execute arbitrary binaries, targeting Windows…

CVE-2025-47273 is a high-severity path traversal vulnerability in the setuptools library ,specifically version 78.1.0 .

VMware exploit

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

a guard that blocks catastrophic agent actions

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…

Non-weaponized CVE-2016-5195 (Dirty COW) analysis and validation harness with root-cause research, upstream patch review, and safe lab-only PoC for…