
AmzWord
An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

Repository to index useful tools for CTF's

This repository is a collection of powershell functions every hacker should know

A list of Capture The Flag (CTF) frameworks, libraries, resources and software for started/experienced CTF players 🚩

CTF Cheat Sheet + Writeups / Files for some of the Security CTFs that I've done

"Bob the Smuggler": A tool that leverages HTML Smuggling Attack and allows you to create HTML files with embedded 7z/zip archives. The tool would…

PoC - Exploit Delivery via Steganography and Polyglots, CVE-2014-0282

Some setup scripts for security research tools.

A collection of awesome penetration testing resources, tools and other shiny things

👶 BabySploit Beginner Pentesting Toolkit/Framework Written in Python 🐍


Curated reading list and taxonomy of attack and defense research for mobile on-device AI systems, covering adversarial, backdoor, model stealing, and…

PHP script and guide for injecting PHP webshells into JPEG images using Jhead. Used to bypass file upload filters and achieve remote command…

Encodes a PowerShell script in the pixels of a PNG file and generates a oneliner to execute

This is the development tree. Production downloads are at:

Malicious PixelCode is a security research project that demonstrates a covert technique for encoding executable files into pixel data and storing…

reverse engineering Gemini's SynthID detection