
stratus-red-team
:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud

:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud

Exploit for the vulnerability CVE-2024-43044 in Jenkins

Demonstrates Apache Camel CVE-2025-27636 with Docker-based reproduction of header injection attacks, including bean method injection and command…

A Streamlined FTP-Driven Command and Control Conduit for Interconnecting Remote Systems.

Research code for red-teaming AI auto-mode monitors, including simulation evals, fuzzing, and monitor implementations for Claude Code and Codex…

Red Team K8S Adversary Emulation Based on kubectl

Check for LDAP protections regarding the relay of NTLM authentication

Curated collection of validated Joomla exploit artifacts with Docker lab environments. Includes RCE, SQLi, XSS, and privilege escalation scripts…

A visual methodology tracking platform tailored for offensive security assessments

Proof-of-concept exploit for CVE-2026-9198, an unauthenticated RCE in IBM Langflow OSS, chaining auto_login and validate/code endpoints. Includes a…

Python-based exploit for CVE-2025-55182 (React Server Components RCE) with interactive shell, reverse shell, batch scanning, and Docker-based…

The code for personally reproducing the corresponding vulnerability

Python PoC and Docker lab for CVE-2026-61500: recovers Rejetto HFS V8 PRNG state to forge an admin session cookie and achieve RCE via server_code.


Autonomous multi-agent AI penetration-testing engine: a governed tool sandbox, an immutable evidence-and-validation gate, and a reproducible…

Lord Of Active Directory - automatic vulnerable active directory on AWS

Public PoC and detector for CVE-2026-20896 ("Gitea Docker: One Header, Any User")

Easily setup a hidden service inside the Tor network