Reach 125K+ monthly visitors

Advertise on Trendshift

Pentesting

New 2026

AI-native security reasoning engine for coding agents

New 2026

A simple tool wrapper to automate the enumeration, fingerprinting, and PSK extraction of an IPSec VPN gateway.

New 2026

Sekizdesekiz grup'daki bir güvenlik açığı

New 2026

Decrypt VMware vTPM-encrypted .vmem/.vmsn/.vmss/.nvram from the VM password, and flatten the .vmem to a Volatility-ready image.

New 2026

Complete QEMU/KVM virtualization lab for Arch Linux with Windows 11, Kali Linux, Ubuntu, Metasploitable2, networking, TPM 2.0, UEFI, VirtIO, and cybersecurity lab setup.

New 2026

Memory-injection-resistant smart contract audit agent — a reference implementation of a secure AI agent

New 2026

Lightweight terminal context and vault variable manager for Linux.

New 2026

Self-hosted AI security lab with fresh LXD workspaces and OpenCode-powered authorized testing

New 2026

VulnScan (Windows Installer and Runs Locally). A locally run vulnerability scanner with port scanning, CVE lookup, VirusTotal integration, and PDF reports

New 2026

CVE-2026-45504 Microsoft Exchange File Read

New 2026

A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz

New 2026

Advanced OPSEC fork of Donut. Features a Custom in-memory CLR Host, Tail-Jump ETW bypasses, and zero-patch AMSI evasion for stealthy shellcode generation.

New 2026

Code and data for our paper "Onelogon: Taking over Active Directory Accounts via Netlogon" (WOOT’26).

New 2026

A foundational C library for building operationally credible offensive capabilities

New 2026

One-command security scanner. 40+ rules for secrets, OWASP and deps. Scanned React: F grade.

New 2026

Unauthenticated RCE PoC for CVE-2026-48908 — SP Page Builder for Joomla (≤ 6.6.1): arbitrary file upload via asset.uploadCustomIcon. Self-cleaning, token-guarded. Authorized testing only.

New 2026

A web pentest agent ensemble for Claude Code — every finding is independently verified and QA-gated.

New 2026

IOC enrichment + PE static analysis in one self-contained Windows CLI. Zero dependencies.

New 2026

Curated security auditors for the backend stack — Supabase, Firebase, Hasura, Strapi, Directus, Payload, Convex, n8n, Ollama & more. Keyless, active-probe, MIT.

New 2026

Six-layer call-stack spoofing via .pdata lacunae — defeats ETW-Ti, kernel callbacks, CET shadow stack, and return-address validation in a single composite chain.

New 2026

BruceButBetter — DIY Flipper Zero on ESP32-S3 N16R8. Downstream Bruce fork: Sub-GHz, NFC/RFID, IR, WiFi/BLE, NRF24 & Si5351 in one device. Browser flasher included.