
security-research
This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned…

This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned…

This repository contains the scanner component for Greenbone Community Edition.

A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak…

This cheasheet is aimed at the CTF Players and Beginners to help them understand the fundamentals of Privilege Escalation with examples.

Shodan Eye This tool collects all the information about all devices directly connected to the internet using the specified keywords that you enter.…

This project has stopped to maintenance, please to https://github.com/knownsec/pocsuite3 project.

This is a resource factory for anyone looking forward to starting bug hunting and would require guidance as a beginner.

This is the development tree. Production downloads are at:

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

This is a repo which documents real bugs in real software to illustrate trends, learn how to prevent or find them more quickly.

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

This skill helps Claude write secure code and prevent common vulnerabilities.

SSMA - Simple Static Malware Analyzer [This project is not maintained anymore by me]

The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

This repository includes code and IoCs that are the product of research done in Akamai's various security research teams.

There is no pre-auth RCE in Jenkins since May 2017, but this is the one!

This is a one-time signature verification bypass. For persistent signature verification bypass, check…