

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

Android deeplink misconfiguration detector and exploitation tool

Self-hosted multi-agent environment for Go with LLM-powered pentesting agents (exploiter, reverser, threathunter, webscanner) that automate…

My experiments in weaponizing Nim (https://nim-lang.org/)

Mind-Maps of Several Things

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

A foundational C library for building operationally credible offensive capabilities


A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution…

A hands-on simulation of CVE-2017-5638 (Apache Struts2 RCE), showcasing exploit reproduction, OS-level command execution, and mitigations such as…

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level