Cyber Security Consultant | Security Team Lead | DevSecOps |
CVE-2025-32463. Local Privilege Escalation to Root via Sudo chroot in Linux
469ICS-Pentesting-Tools. A curated list of tools related to Industrial Control System (ICS) security and Penetration Testing
357Ransomware-Samples. Small collection of Ransomware organized by family.
292Malware-Analysis. A curated list of awesome malware analysis tools and resources
168smartrecon. smartrecon is a powerful shell script to automate the recon and finding common vulnerabilities for bug hunter
159cloud-penetration-testing. A curated list of cloud pentesting resource, contains AWS, Azure, Google Cloud
151exchange-penetration-testing. The great Microsoft exchange hack: A penetration tester’s guide (exchange penetration testing)
140bug-bounty-writeups. A curated list of available Bug Bounty & Disclosure Programs and Write-ups.
82Apache-Tomcat-Pentesting. Apache Tomcat exploit and Pentesting guide for penetration tester
66Penetration-Testing-Interview-Questions. Penetration Testing Interview Questions
59WAF-Bypass. 🔥 Web application firewalls (WAF) bypass
57security-mindmap. This repository stores various roadmap(Mindmaps) for bug bounty Hunter, pentester, offensive(red team), defensive(blue team) and security Professional people
56ProxyShell. CVE-2021-34473 Microsoft Exchange Server Remote Code Execution Vulnerability
41Shodan-Dorks. a curated list of shodan dorks for finding sensitive data in shodan.io
40Ransomware. Ransomware Simulator for Blue team ,Ransomware Simulator for Red team ,Ransomware infographic, open source Anti Ransomware, Ransomware As A Service and Ransomware protection technologies
35wifi-password-stealer. steal saved wifi passwords in a computer & ip of target then report them through email.
33Application-Security-Interview-Questions. Here are some common interview questions for an application security position you can review for your own interview, along with example answers
33ElasticSearch-Pentesting. ElasticSearch exploit and Pentesting guide for penetration tester
31MQTT-Pentesting. MQTT exploit and Pentesting guide for penetration tester
31xmlrpc-exploit. Exploiting the xmlrpc.php on all WordPress versions
29RabbitMQ-Pentesting. RabbitMQ exploit and Pentesting guide for penetration tester
20DevSecOps. Collection and Roadmap for everyone who wants DevSecOps, contains list of tools and methodologies
18Cloud-Flaws-CTF. flAWS.cloud and flAWS2.cloud Interactive tutorial/CTFs to learn common AWS security mistakes.
16CVE-2022-23131. Zabbix - SAML SSO Authentication Bypass
15Spring-CVE. This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux RCE termed "SpringShell".
14FFUF-Tricks. Describe how to use ffuf different options with examples
14Grafana-CVE. a Curated list of Grafana Security Vulnerabilities, CVE & exploit
12bruteforce-http-authentication. Bruteforce HTTP Authentication. Supports: Basic HTTP authentication ,Digest HTTP authentication
12Bug-Hunting-Handbook. Bug Hunting Handbook
12Nextcloud-Pentesting. Nextcloud exploit and Pentesting guide for penetration tester
10Smishing-Botnets. Smishing Botnets Going Viral in Iran
10ProxyLogon. ProxyLogon (CVE-2021-26855+CVE-2021-27065) Exchange Server RCE (SSRF->GetWebShell)
9Cyber-Threat-Hunting. A curated list of threat detection and hunting resources
9CVE-2023-38646. Metabase Pre-auth RCE (CVE-2023-38646)
9Webmin-CVE. a Curated list of Webmin vulnerability for penetration tester
8Fresh-Resolvers. List of fresh DNS resolvers updated daily
7Cybersecurity-Awareness-Training. 🛡️ Cybersecurity Awareness Training for Employees
6Active-Directory-Attacks. A curated list of awesome Active Directory Penetration Testing and attack resources
6DDoS-Attack. DDoS Attack and type of ddos attack and ddos mitigation approach
6Splunk. a useful tutorial about splunk and security splunk app
5CVE-2023-22515. CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server
5open-DNS-resolver. DNS Open resolvers or Open DNS resolver vulnerability are type of DNS amplification attack.
5Favicon-Hash. Calculate Favicon Hash for Shodan
5CVE-2022-26134. [PoC] Atlassian Confluence (CVE-2022-26134) - Unauthenticated OGNL injection vulnerability (RCE)
4PHP-Interview-Questions. a curated list of php interview questions and answers
4nuclei-templates. Community curated list of templates for the nuclei engine to find security vulnerabilities.
3GitLab-SSRF-CVE-2021-22214. POC for CVE-2021-22214: Gitlab SSRF
3Threat-Modeling. Threat Modeling and tools
3cyber-attacks-in-iran. A curated list of awesome cyber attacks in iran, we want to review and explain some advanced attack that happened in iran, in order to learned some security tips.
3FortiWeb. FortiWeb is a web application firewall (WAF)
2CVE-2025-34152. Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE (CVE-2025-34152)
2CVE-2021-30573. Google Chrome Vulnerabilities CVE-2021-30573 allowed a remote attacker to potentially exploit heap corruption
2Offline-Pentest-Toolkit. Offline Penetration Testing Toolkit & Methodologies
2Amsi-Bypass. This repo contains some Amsi Bypass methods i found on different Blog Posts.
1Awesome-Code-Review. Awesome list of code review resources and tools
1Redis-Pentesting. Redis exploit and Pentesting guide for penetration tester
1