cve-2024-20017. exploits for CVE-2024-20017
139santa-linux. A proof-of-concept Linux clone of Santa, Google's binary authorization system for macOS
34mediarekt-2025. PoCs for Mediatek CVEs affecting MT7622/MT7915 and others
23mt7622-qemu-vm. QEMU emulation of MediaTek MT7622 PCI driver
21cve-2023-33476. Exploits for a heap overflow in MiniDLNA <=1.3.2 (CVE-2023-33476)
19rpi-tap. Build a Raspberry Pi Ethernet tap/bridge.
12kernel-utils. some scripts to automate setting up kernel research and development environments
10bro-stash. Collect and parse Bro logs with Logstash+Filebeat
8hyperecon. recon setup + automation
7santa-bypass. A Santa bypass using in-memory binary loading and execution + Python ctypes for stealth
6keysniffer-poc. Simple PoC Linux keysniffer showing impact of a lack of GUI-isolation in X display server.
5c2finder. Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)
5wifi-berry. Turn your RPi 3 into a wireless access point, quick and easy.
5udhcpd-fuzz. fuzzing udhcpd with afl llvm persistent mode fuzzing
3sploits. PoC exploits for bugs I have found and disclosed.
3mtk-kernel-alchemy. C
3elasticsec. Read different security-related data formats into a portable ELK stack.
2payloads. Git All the Payloads! A collection of web attack payloads.
2awesome-reversing. A curated list of awesome reversing resources
1linux-kernel-exploitation. A collection of links related to Linux kernel security and exploitation
1afl-harness. afl harness templates/library
1Cheatsheets. Penetration Testing/Security Cheatsheets
1umap2. Umap2 is the second revision of NCC Group's python based USB host security assessment tool.
1post-install-scripts. Linux post-installation scripts for installation of different tools and sets of tools.
1nestopia. A (slightly) improved fork of 0ldsk00l's Nestopia emulator w/ a GUI
1