
vcsa-hardening-tool
Automated Zero Trust hardening and forensic auditing for VMware vCenter Server Appliance (VCSA)

Automated Zero Trust hardening and forensic auditing for VMware vCenter Server Appliance (VCSA)

Automates BloodHound integration with Cobalt Strike to discover AD escalation paths, mark compromised assets as owned, and investigate beacon…

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs

A deep dive into two critical Sudo vulnerabilities (CVE‑2025‑32463 & CVE‑2025‑32462) that enable local privilege escalation across major Linux…

Exploit for CVE-2022-22639, a macOS Monterey root privilege escalation vulnerability, with Objective-C source code and compilation instructions.

Demonstrates CVE-2026-3030 prototype pollution in a Node.js JSON merge patch REST API, including a vulnerable server and exploit script for privilege…

Proof-of-concept exploit for CVE-2026-31431 (Copy Fail), a Linux kernel LPE via algif_aead page-cache corruption, with detection, lab, and mitigation…

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Android customization suite providing root access (MagiskSU), systemless module installation, boot image unpacking/repacking, and Zygisk runtime code…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

A collection of awesome penetration testing resources, tools and other shiny things

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

A collection of links related to Linux kernel security and exploitation

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

Tools and Techniques for Red Team / Penetration Testing

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

Comprehensive red teaming notes covering offensive security techniques including code injection, defense evasion, lateral movement, and persistence,…

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)