
OneListForAll
Curated, categorized wordlist generator for web fuzzing, directory enumeration, and subdomain discovery. Automatically syncs 36+ sources, classifies…

Curated, categorized wordlist generator for web fuzzing, directory enumeration, and subdomain discovery. Automatically syncs 36+ sources, classifies…

The remediation script should set the reg entries described in https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36884 . The detection…

High-speed DNS resolver and subdomain bruteforcer with accurate wildcard filtering and DNS poisoning validation for precise reconnaissance.

Golang tool which helps dropping the irrelevant entries from your ffuf result file.

Buffer overflow in FreeFloat FTP Server 1.0 illustrating how a single unsafe handler can generate multiple CVE entries across different commands.

Displays an old-school crack-intro animation on compromised Canon and Lexmark printers, with SDL2 and WebAssembly builds for portability and study.

Trace every shell environment variable to its exact file and line origin. Audit shell configs for dead entries, duplicates, and orphaned files across…

Proof-of-concept demonstrating an incorrect access control vulnerability in Unifiedtransform v2.0, allowing teachers to create syllabus entries…

ACEshark is a utility designed for rapid extraction and analysis of Windows service configurations and Access Control Entries, eliminating the need…

A practical attack framework for precise enclave execution control

Annual small file competition repository with binary golf challenges across themes like polyglots, crashes, self-replication, and downloads,…

Go library for parsing and executing Sigma detection rules against log entries, supporting field modifiers, CIDR matching, and custom field resolvers…

Checkmk extension that scans JAR, WAR, EAR, and AAR files for Log4j versions vulnerable to CVE-2021-44228 by inspecting META-INF pom.properties…

Hands-on CVE triage lab: analyze NVD entries, decode CVSS vectors, map CWE weaknesses, and contextualize risk for high-profile exploits like…

Curated database of vulnerable and malicious Windows drivers with YARA, Sigma, ClamAV, and Sysmon detection rules for proactive threat hunting and…

Nail in the JKS coffin - Cracking passwords of private key entries in a JKS file

Parser for $LogFile on NTFS

Proof-of-concept exploit for XenForo CVE-2026-73318, an authorization bypass allowing ACP administrators to trigger site-wide policy re-agreement.…