
BEAR-C2
The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Docker lab reproducing CVE-2026-53519, a pre-auth path traversal in Nezha Dashboard that leaks jwt_secret_key and enables JWT forgery and admin…

Official QEMU mirror. Please see https://www.qemu.org/contribute/ for how to submit changes to QEMU. Pull Requests are disabled. Please only use…

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Go Trusted Execution Environment (TEE)

ArmourBird CSF - Container Security Framework

eBPF LSM program that blocks AF_ALG socket creation to mitigate CVE-2026-31431, with userspace daemon logging denied attempts via ring buffer.

iPhone 11 emulated on QEMU

Apple Silicon device emulator.

🛡️ Windows Hello™ style facial authentication for Linux

A PS5 hypervisor exploit for 1.xx-2xx firmwares.

RISC-V Virtual Machine

A Linux framework to enable userspace-defined "Virtual" PCIe card shims to enable in-host PCIe card driver development.

Run untrusted AI code safely, fast

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Virtual Security Operations Center

Windows Process Lockdown Tool using Job Objects

Zapscape (CVE-2026-64561) KVM/x86 shadow MMU UAF guest-to-host escape PoC mirror — V4bel/@v4bel, MIT; for authorized security testing