
sharepoint-toolshell-micro-postmortem
Reproducible incident micro-postmortem for on-prem Microsoft SharePoint “ToolShell” (CVE-2025-53770): ATT&CK snapshot, “logs that matter” table,…

Reproducible incident micro-postmortem for on-prem Microsoft SharePoint “ToolShell” (CVE-2025-53770): ATT&CK snapshot, “logs that matter” table,…

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Secure-by-default demo lab showing how container hardening (distroless images, non-root, read-only filesystem, runtime-injected secrets) can…

Unauthenticated arbitrary file upload exploit for WooCommerce Return Refund and Exchange plugin (CVE-2022-4047). Scans targets, uploads webshell, and…

A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted…

Exploit scanner for CVE-2024-24919 targeting Check Point Security Gateways. Scans IP lists, extracts /etc/passwd, /etc/shadow, and system logs from…

Springboot web application accepts a name get parameter and logs its value to log4j2. Vulnerable to CVE-2021-44228.

Python script to scan websites for CVE-2023-6895 vulnerability. Sends crafted requests, checks responses, and logs exploitable URLs with progress bar…

Quick One Line Powershell scripts to detect for webshells, possible zips, and logs.

Terminal UI for browsing and replaying AWS WAF v2 logs from CloudWatch, S3, and the sampling API, with YAML filtering, auth detection, and…


Redirect All Traffic Through Tor Network For Kali Linux

Zero-Knowledge Credential Sharing

CVE-2020-0618 Honeypot

Stored XSS in TastyIgniter v3.0.7 Restaurtant CMS

Public reference for CVE-2025-56643 – Wiki.js 2.5.307 JWT Session Vulnerability

CVE-2025-10377

Citrix ADC (NetScaler) Honeypot. Supports detection for CVE-2019-19781 and login attempts