
CloudPrivs
Determine privileges from cloud credentials via brute-force testing.

Determine privileges from cloud credentials via brute-force testing.

pytest for AI agents - Autonomous red-teaming, behavioral monitoring & security testing for LLM agents

Build anti-detection Frida server from source. ~90 patches covering 16 detection vectors, weekly auto-builds with random names.

Project Mantis: Hacking Back the AI-Hacker; Prompt Injection as a Defense Against LLM-driven Cyberattacks

A curated set of NSO Group internal documents, product materials and sworn testimony that entered the public record in WhatsApp Inc. and Meta…

This repository provides a learning environment to understand how an Exim RCE exploit for CVE-2018-6789 works.

Set up a personal VPN in the cloud

Terraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational…

Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier

Pivotal CRM's patch for an initial deserialization vulnerability was incomplete. The fix switched from BinaryFormatter to JSON.NET but left…

Automatically deploying Mythic C2 in Azure using Terraform

An AWS CloudFormation template used to provision and manage AWS WAFv2 resources, including a Web ACL, managed rule groups, a custom regex pattern…

Cryptographic protocol library enabling privacy-preserving set membership queries where the server learns neither the client's identifier nor the…

Step-by-step guide to building custom Kali NetHunter kernels for Android: source retrieval, toolchain selection, cross-compilation, and flashing.

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

Set of tools to audit SIP based VoIP Systems

OWASP Thick Client Application Security Verification Standard