
RedGhost
Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…


Local-first encrypted password manager for logins, notes, and API keys, using a SQLite vault sealed with Argon2id and XChaCha20-Poly1305; no cloud or…

Generates fully valid fake identities in Spanish format, including names, emails, bank details, and extended info, with optional zip compression and…

Track the GPS location of the user's smartphone or PC and capture a picture of the target, along with IP and device information.

A Chrome extension that demonstrates bypassing Widevine L3 DRM

Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and leaving no…


All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Generates fully valid fake identities in Spanish format, including names, emails, bank details, and extended info, with optional zip compression and…

Track the GPS location of the user's smartphone or PC and capture a picture of the target, along with IP and device information.

A Chrome extension that demonstrates bypassing Widevine L3 DRM

Open-source IoT Platform - Device management, data collection, processing and visualization.

A vulnerability scanner for container images and filesystems

Reproduction environment and proof-of-concept for Spring Cloud Function SpEL injection leading to remote code execution, with a runnable Java 11 demo…

Take over macOS Electron apps' TCC permissions

Generates a malicious Microsoft Word document exploiting the MS-MSDT 'Follina' vulnerability to execute arbitrary commands or stage payloads via an…

Detects unknown jailbreak attacks in large vision-language models using hidden state analysis and autoencoders, with training and evaluation…

Agentic Framework for Synthesizing CodeQL Queries

Beacon Object File (BOF) implementation of the dnscmd.exe functionality used to obtain remote code execution on an ADIDNS server by exploiting the…

Evidence-focused malware reverse engineering with deep PE/.NET inspection, Ghidra reconstruction, AI cross-checks, YARA, and ELF debugging

An empirical security testbed evaluating prompt injection, confused-deputy vulnerabilities, and tool-calling defenses in LLM agents.

Research project reverse-engineering Windows Security Center COM interfaces to trace AV registration through ATL, vtable, WSCAPI, and RPC, with…

Deserialization payload generator for a variety of .NET formatters