
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Proof-of-concept exploit scripts for CVE-2024-8068 and CVE-2024-8069, focused on authorized penetration testing, educational labs, and defensive…

Educational security research repository for testing and learning vulnerability concepts, sandboxing, secure coding, and defensive practices in…

Educational repository for documenting and testing CVE proof-of-concept exploits inside isolated labs, virtual machines, and authorized penetration…

Multithreaded Python scanner for CVE-2026-15826 and CVE-2026-15748; checks target lists, supports verbose logging, configurable threads, and custom…

Proof-of-concept exploit resources for CVE-2026-19650 and CVE-2026-19478 targeting a GitLab GraphQL vulnerability, intended for authorized research,…

Audits GitLab projects against the CIS GitLab Benchmark via read-only API checks, generating JSON reports on compliance and hardening recommendations.

Educational CVE proof-of-concept repository with lab scripts for reproducing, testing, and analyzing specific vulnerabilities in isolated…

Reproduces CVE-2021-41773 path traversal in Apache HTTP Server 2.4.49, with PoC code, root-cause analysis, impact assessment, and mitigation guidance…

CS50's Introduction to Cybersecurity final project on React2Shell (CVE-2025-55182)

Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)

Validates and confirms the presence of CVE-2026-58231 in authorized environments via a lightweight Python script for vulnerability research,…

Proof-of-concept CVE exploit and lab scripts for sandbox/VM isolation, targeting authorized environments such as Docker and virtual machines for…

Ruby 4.0 Universal RCE Deserialization Gadget Chain - Draft or TODO

Educational CVE proof-of-concept repository with setup guidance for authorized vulnerability research using virtual machines, Docker, and isolated…

CVE-2026-68820 - Draft or TODO

Technical analysis of CVE-2025-55182 (React2Shell), covering vulnerability mechanics, root cause, controlled PoC testing, impact, and mitigation…

Security research — PoC for local root privilege escalation on macOS Mavericks 10.9.