
compromised-packages
StepSecurity owned org for analyzing compromised packages

StepSecurity owned org for analyzing compromised packages

Local privilege escalation exploit for CVE-2018-14665 targeting X.Org Server on OpenBSD and Linux. Provides a proof-of-concept script to gain root…

Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files

Reproducible incident micro-postmortem for on-prem Microsoft SharePoint “ToolShell” (CVE-2025-53770): ATT&CK snapshot, “logs that matter” table,…

MSI Modern 15H AI C1MGT-096IT Linux thermal management - Reverse engineered EC control with fan profiles and battery threshold

Proof-of-concept exploit for CVE-2018-14665, a local privilege escalation in Xorg on Linux distributions, with analysis and PoC for Red Hat.

Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

Self-hosted CTF control plane for security-learning events: team registration, live leaderboard, and patch-to-score, quiz, jeopardy, and AI challenge…

PyExfil — Python 3 toolkit for researching and stress-testing data exfiltration techniques across network, physical, and steganographic channels. For…

Automated GitHub dorking tool that searches user, organization, and repository code for exposed secrets, credentials, and security misconfigurations…

Simple TCP tunnel in Rust that exposes local ports to a remote server, bypassing NAT firewalls. Lightweight, self-hostable, and easy to install.

🖇 Enumerate git repository URL from list of URL / User / Org. Friendly to pipeline

UNIX-like reverse engineering framework and command-line toolset.

A PowerShell script that automates the security assessment of Microsoft 365 environments.

CLI tool to find email addresses of GitHub users, contributors, and organization members, with multi-threading, JSON output, and breach checking via…

A Full-Featured HexEditor compatible with Linux/Windows/MacOS

A tool to help you manage your leaks

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR