PoC_CVEs
-
Updated
May 16, 2026 - Shell
PoC_CVEs
A Universal Android NFC research and analysis toolkit. Made for Android security researchers and developers. Clone, analyze, and test contactless cards including MIFARE, NTAG, and ISO14443 protocols. Features card data extraction, analysis tools, and emulation capabilities for penetration testing and research.
Minimal no-libc Linux x86_64 ELF PoC build for Copy Fail (CVE-2026-31431)
Unstripped iOS kernel extensions and more. More coming soon.
Investigation toolkit for Claude Code: case management, OSINT, structured analytic techniques, chain-of-custody evidence capture, and bundled threat-intel MCP servers.
Comprehensive operational knowledge base: OSINT, forensics, reverse engineering, malware analysis, cryptography, smart-contract audit, cloud/AD/web pentesting, blockchain tracing, and intelligence frameworks for security researchers and CTF players.
CamHawk is a camera phishing tool that tricks users into granting webcam access. Once permission is granted, the tool captures images from the webcam and sends them to your machine.
Outside-in replication of Anthropic's Mythos Preview / Project Glasswing — open-source agentic vulnerability-discovery scaffold on Claude Opus 4.7. Eight-phase sink-guided pipeline, ~$1/run, OSS self-scan and coordinated disclosure.
Script that performs a scan of a specific domain, using the following tools: Subfinder, assetfinder, amass and httpx. The result is merged into one file.
AI-powered security research assistant for Claude Code — structured assessment workflows, tool orchestration, and professional reporting across recon, enumeration, vulnerability scanning, and secrets auditing. Built for security researchers and bug bounty hunters who want Claude as an analyst, not a command generator.
Eddie Vetter - triage macOS applications for security research
Automatic Enumeration is a command line utility that automatically tries to collect and retrieve various pieces of information from a target machine during red team operations
AKQ_0D_PE is a lightweight and powerful Zero-day local privilege escalation exploit targeting a critical vulnerability in the Linux PipeFS subsystem.
A simple bash toolkit to deploy a Web Vulnerability Lab on Ubuntu Server. Automatically installs 9 vulnerable apps (OWASP Juice Shop, WebGoat, DVWA, bWAPP, Mutillidae II, XVWA, VWA, WebWolf, Tomcat) containing exactly 401 vulnerabilities for safe hacking practice.
Automated evil twin access point toolkit with traffic capture and real-time monitoring for wireless penetration testing and security research.
Vulnerability research on Tesla Model 3/Y infotainment systems. 6 vulnerabilities, 4 CVEs (CVE-2022-42005 through CVE-2022-42008). Root shell, persistent access, insurance telemetry spoofing.
LocHawk is a powerful geolocation phishing tool that tricks targets into revealing their exact GPS location, device information, and network details through a seemingly harmless webpage.
Android GDB Automation
Add a description, image, and links to the security-research topic page so that developers can more easily learn about it.
To associate your repository with the security-research topic, visit your repo's landing page and select "manage topics."