Pentesting
Vulnerability assessment and penetration testing of Metasploitable2 in an isolated VMware laboratory environment.
Pre-authentication RCE in Cisco CUCM 15.x via Apache Axis JNDI injection — independent chain, survives Silent;Call patches
Pre-authentication SIP request smuggling in Cisco Expressway X14.x via Content-Length integer overflow
Detection-aware BloodHound attack-path scoring - find the quietest route to your objective, calibrated across audit/EDR/SIEM tiers.
AuditSentry — AI-powered smart contract security auditor for Claude Code. Automated vulnerability detection, exploit PoCs, mainnet-fork simulation, and professional audit reports for Solidity & Vyper across all EVM chains.
PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp
Cyber-Security-Lab-Setup
This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level development. It brings together the research, experiments, implementations, findings, and progress made throughout the project, providing a structured overview of the work from basic to advanced stages.
Exploiting the .lnk vulnerability and operating system handling mechanisms regarding explorer.exe and USB drives.
A managed fleet of intentionally-vulnerable apps (Juice Shop, DVWA, WebGoat, VAmPI, crAPI, faultline, and more) to point security scanners and recon tools at. One manager runs each target as its own isolated container stack, with per-app ground-truth vuln catalogs. Local testing only.
DJI SkyPixel mc/user/search — 42k+ email enumeration via hardcoded WuKong credentials
PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)
"Reverse engineering analysis of Agent Tesla, a .NET-based info-stealer that uses APC injection, token manipulation, and registry persistence. Includes NtQueueApcThread, NtProtectVirtualMemory, and full payload extraction."
Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)