
gha-lab-232af4821f
Security-research lab reproducing CVE-2021-4281 (GHSA-3796-3f93-cfvx): shell command injection via PR head-branch name in…

Security-research lab reproducing CVE-2021-4281 (GHSA-3796-3f93-cfvx): shell command injection via PR head-branch name in…

Ressources and papers related to my conferences and work on (un)RASPs. These work is in progress, please be patient :) Don't hesitate to contribute /…

Current links from the OSINT Inception start-me project

Curated timeline of AWS S3 bucket misconfigurations, exposed data, and leaked IAM credentials, with incident links for cloud security defenders and…

Nuclei templates for drupal vulns... far from perfect

Local linux kernel DoS based on memleak from an unpriv user, just need to do a PR_TIMER_CREATE_RESTORE_IDS_ON prctl first based on…

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Broadpwn bug (CVE-2017-9417)

Reproducible lab for CVE-2020-0610 (BlueGate) - Windows RD Gateway UDP/DTLS remote code execution vulnerability. Includes PowerShell scripts, setup…

CVE-2024-37051 poc and exploit

PoC for CVE-2020-6287 The PoC in python for add user only, no administrator permission set. Inspired by @zeroSteiner from metasploit. Original…

GitHub Action for Heisenberg SSC

A list of Capture The Flag (CTF) frameworks, libraries, resources and software for started/experienced CTF players 🚩