
adversary_emulation_library
An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

Curated collection of cybersecurity research reports covering CVE analysis, exploit research, threat intelligence, and offensive security from…

Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects…

Reproduction of CVE-2025-55182 (React2Shell): pre-auth RCE via unsafe deserialization in React Server Components Flight protocol. Includes PoC…

Nuclei-based detection template for CVE-2025-53690 (Sitecore deserialization RCE). Designed for defenders to identify potentially vulnerable Sitecore…

Educational demonstration of CVE-2025-42957: an RFC-enabled SAP S/4HANA module vulnerability allowing low-privileged ABAP injection for admin account…

Comprehensive PoC and detection toolkit for CVE-2025-5777 (CitrixBleed 2), an out-of-bounds memory read in NetScaler ADC/Gateway. Includes exploit…

High-performance Rust HTTP/HTTPS proxy with active defense: rate limiting, reputation-based access, WAF (anti-bot, anti-injection, path protection),…

Python PoC for CVE-2026-8181, a critical authentication bypass in Burst Statistics WordPress plugin. Includes exploit automation, bulk scanning, and…

C-based XLL payload development for phishing campaigns, with techniques for delivery via ZIP containers, self-deletion, and evasion of AV/EDR and…