
CVE-2025-39964
Patch-status tracker for CVE-2025-39964, a Linux AF_ALG race condition enabling local privilege escalation, recording per-distribution fix…

Patch-status tracker for CVE-2025-39964, a Linux AF_ALG race condition enabling local privilege escalation, recording per-distribution fix…

Reverse engineering notes, deobfuscated source, IOCs, and YARA rules for the Tourmaline ClickFix Python RAT, covering its DNS tunnel and blockchain…

CVE-2026-42978 Windows Push Notifications (WpnService) Use-After-Free & Race Condition PoC research, diagnostic scanner, and security audit module…

A resource containing all the tools each ransomware gangs uses

IOCs and a read-only triage checklist from a real Linux root compromise: RedTail miner, XorDDoS persistence, MoneroOcean miner, DirtyFrag LPE…

Hands‑on analysis of CVE‑2025‑62215, a Windows Kernel race condition exploited in the wild. Demonstrates privilege escalation to SYSTEM, detection…

Fake exploit tool, designed to rickroll users attempting to actually exploit.

Automated detection and tracking of fake engagement on GitHub — daily CI, zero infrastructure

Hunt down social media accounts by username across social networks

Sigma detection rule for MiniPlasma (CVE-2020-17103)

Minecraft Honeypot for Log4j exploit. CVE-2021-44228 Log4Shell LogJam

Krawl is a customizable, lightweight, cloud-native web deception server and anti-crawler that creates fake web applications with low-hanging…

Full static analysis of HyperHives macOS Rust infostealer — 571 decrypted config values, C2 infrastructure, DPRK/Contagious Interview attribution,…

Automated, Collection, and Enrichment Platform

honeyλ - a simple, serverless application designed to create and monitor fake HTTP endpoints (i.e. URL honeytokens) automatically, on top of AWS…

A python package for use in generating fake data for SOC and security automation.