
vulnerability-poc
CVE proof-of-concept labs, exploit scripts, and detection/prevention rules (Nginx, Apache, Snort, YARA) for high-severity CVEs. Authorized security…
Short editorial updates from published cybersecurity tools.

CVE proof-of-concept labs, exploit scripts, and detection/prevention rules (Nginx, Apache, Snort, YARA) for high-severity CVEs. Authorized security…

Technical disclosure: Credential fabrication via XML tag injection in Claude Sonnet 4.6. Reported June 14 2026, patched June 18 2026.

Python client for dnsdumpster.com to retrieve DNS records, subdomains, and network maps for reconnaissance and security research.

Native C++ reverse-engineering engine with disassembly, decompilation, and analysis pipeline for PE/ELF binaries, featuring interactive GUI and…

Curated repository of Qubes OS security bulletins, canaries, PGP keys, and ISO digests, with authenticated verification via git tags and detached…

Browser-based risk analysis editor for building risk matrices, risk registers, and action plans. Supports EBIOS RM, ISO 27005, and CNIL DPIA with…

A curated list of Web3 Security materials and resources for Pentesters and Bug Hunters.

OSCP field notebook: merged technique vault and numbered notes. MIT.

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

Security control plane for LLM agents: allowlists, owner kill switch, PIN sessions, rate limits, prompt-injection detection, and output scrubbing to…

Detection-engineering reference mapping Windows, cloud, container, identity, and ICS attack classes to Sigma rules, trust-boundary models, BYOVD…

Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.