
ZSC
OWASP ZSC - Shellcode/Obfuscate Code Generator https://www.secologist.com/

OWASP ZSC - Shellcode/Obfuscate Code Generator https://www.secologist.com/

The most comprehensive LLM + MCP security guide i.e. OWASP aligned, real CVEs, actionable checklists

Python exploit for CVE-2026-16764, a privilege escalation in OWASP DefectDojo where an is_staff REST API bypass lets a low-privileged user gain…

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security


Proof-of-concept exploit for CVE-2022-23808, a stored XSS vulnerability in phpMyAdmin 5.1.1 setup script, with payload and reproduction steps for…

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

Proof-of-concept exploit for CVE-2023-27532 in Veeam Backup and Replication that abuses an unsecured API endpoint to extract credentials from the…

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…

Public PoC Disclosure for CVE-2020-23839 - GetSimple CMS v3.3.16 suffers from a Reflected XSS on the Admin Login Portal

The WASM Based Security Toolkit for the Web First Paradigm

Open-source adversary emulation for AI agents and MCP servers.

pytest for AI agents - Autonomous red-teaming, behavioral monitoring & security testing for LLM agents

Open-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.

An empirical security testbed evaluating prompt injection, confused-deputy vulnerabilities, and tool-calling defenses in LLM agents.

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

Open-source prompt injection attack console. Test AI security by firing categorized attacks at any endpoint.