
agentic-threat-hunting-framework
ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.

ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.

Vulnerable app with examples showing how to not use secrets

CVE-2026-87902 detector. WordPress get_page_template LFI class. Detect-only. Authorized lab.

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

GRC platform for risk management, compliance, and audit with 200+ frameworks, automatic control mapping, vulnerability management, and incident…

NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…

Reflected XSS via search GET Parameter in Phoca Download

Reflected XSS via price_from & price_to Filter Parameters in PhocaCart

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3

PoC for CVE-2026-18953 — arbitrary file write (CWE-22) in awslabs.aws-transform-mcp-server's get_resource tool via the savePath parameter

Stack buffer overflow PoC for a hardware wallet USB descriptor parser (CVE-2026-22013), showing return-address overwrite and code execution via…

Parallel SSH service discovery and security auditor that scans any port, validates SSH banners, and audits authentication methods, weak cryptography,…

Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)

Exploit for CVE-2025-64512 to get a reverse shell.

Exploit script chaining CVE-2026-53595 (anonymous account takeover) and CVE-2026-53593 (.pht upload) for unauthenticated remote code execution on…

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer