
maps_scanner
MAPS cloud scanner and response parser for Microsoft Defender research.

MAPS cloud scanner and response parser for Microsoft Defender research.

Patched version of Expat XML parser for AOSP10, addressing CVE-2022-25236. Provides source code for vulnerability analysis and educational review of…

Forensics tool for NTFS (parser, mft, bitlocker, deleted files)

SQL / SQLI tokenizer parser analyzer

C library for stream-oriented XML parsing, providing a fast and configurable parser with support for custom handlers and encoding options.

Proof-of-concept exploit for Redis 8.2.1 Lua parser use-after-free, racing garbage collection via crafted loadstring calls to achieve remote code…

Proof-of-concept exploit for CVE-2023-21716, a critical remote code execution vulnerability in Microsoft Word. Demonstrates exploitation of the…

Struts2 Application Vulnerable to CVE-2017-5638. Explains how the exploit of the vulnerability works in relation to OGNL and the JakartaMultiPart…

Demonstrates XXE via SVG upload with a vulnerable Flask/lxml parser and an exploit script for arbitrary file read, SSRF, and denial-of-service…

Security advisory for CVE-2026-66731 with root cause analysis, PoC exploit, and fix suggestions for facil.io HTTP/1.1 chunked encoding parser bug.

Vulnerable test environment for CVE-2020-13756 (Sabberworm PHP CSS Parser RCE)

Go library for parsing and executing Sigma detection rules against log entries, supporting field modifiers, CIDR matching, and custom field resolvers…

Documentation of a denial-of-service vulnerability in the Rizin reverse engineering framework's ELF parser, caused by a forged DT_VERNEEDNUM value…

Stack buffer overflow PoC for a hardware wallet USB descriptor parser (CVE-2026-22013), showing return-address overwrite and code execution via…

Simulated 5G gNodeB NAS parser with stack buffer overflow PoC for CVE-2026-23002; a crafted NAS message triggers remote code execution.

Source code repository for Expat 2.1.0, a stream-oriented XML parser library, with focus on analyzing and addressing CVE-2022-43680.

Exploit script for CVE-2024-23897, leveraging Jenkins CLI command parser misconfiguration to read arbitrary files on unpatched Jenkins controllers…

Tests hundreds of URL bypass techniques against 40X protected pages using raw curl requests, with multi-mode scanning, header spoofing, and JSON/HTML…