
Guardrails
Programmable guardrails for LLM chat apps: enforce input/output rails, block jailbreaks and prompt injections, detect hallucination, and mask…

Programmable guardrails for LLM chat apps: enforce input/output rails, block jailbreaks and prompt injections, detect hallucination, and mask…

A vulnerable version of Rails that follows the OWASP Top 10

A library for detecting known secrets across many web frameworks

Vulnerability scanner using Nmap for scanning and correlating found CPEs with CVEs.

Proof-of-concept exploit for CVE-2022-21971, demonstrating an uninitialized pointer free in Windows prauthproviders that triggers remote code…

Proof-of-concept exploit for CVE-2019-5418, demonstrating file content disclosure on Ruby on Rails via crafted Accept headers, with a demo…

RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)

Exploit for Apple CoreGraphics heap overflow (CVE-2014-4377) enabling arbitrary code execution on iOS 7.1.x via crafted PDF used as HTML image.

Proof-of-concept exploit for CVE-2020-8163, a remote code execution vulnerability in Rails < 5.0.1 via user-controlled locals, with a testable…

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

PoC and root-cause analysis for CVE-2022-21974, an uninitialized pointer free in RMSRoamingSecurity that yields remote code execution via crafted RTF…

Proof-of-concept exploit for CVE-2020-8165 (Ruby on Rails) demonstrating remote code execution via ERB template injection and deserialization. For…

Generates malicious RTF files exploiting CVE-2017-11882 to execute arbitrary commands on vulnerable Microsoft Office installations.

Forensic toolkit and agent skills for investigating Rails Active Storage/libvips CVE-2026-66066: detects crafted blob indicators, exposure windows,…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

Reproducible lab for CVE-2026-66066: file-read-to-RCE exploit chain via Ruby on Rails Active Storage and libvips HDF5 matload. Includes Python…

Remote Code Execution on Microsoft Exchange Server through fixed cryptographic keys

Proof-of-concept exploit for CVE-2014-0130, a Rails directory traversal vulnerability. Demonstrates path traversal payload and references HackerOne…