List of @Mohadsec Research & Open Source Projects
- CVE-2026-8795: Velociraptor YAML injection allows arbitrary execution on the analyst's machine
- AI SOC agent & MCP server for automated security investigation, alert triage, and incident response Blackhat MEA 2025
- CVE-2025-59287: WSUS SoapFormatter RCE Investigation & Honeypot Analysis
- Velociraptor artifact for automated Thor YARA scanning
- Deployment and testing platform for Velociraptor's client artifacts
- RamiGPT: Autonomous Privilege Escalation AI agent
- CyRC Advisory: CVE-2024-5185 - AI Web Application Data Poisoning Vulnerability
- Git Scanner: Detect Sensitive Data in Organization Repositories
- Nmap Detection Scripts for CVE-2022-45477, CVE-2022-45479, CVE-2022-45482, CVE-2022-45481
- CyRC Advisories: CVE-2022-45477, CVE-2022-45478, CVE-2022-45479, CVE-2022-45480, CVE-2022-45481, CVE-2022-45482, CVE-2022-45483 - Remote Code Execution Vulnerabilities in Different Mouse and Keyboard Applications
- Multiple RCEs in Different Mouse and Keyboard Applications
- Nginx 0.6.18 < 1.20.1 Memory Overwrite Vulnerability Proof of Concept CVE-2021-23017
- Automating the build of a Vulnerable AD environment (IaC)
- Multiple Web Vulnerabilities on Rumble Mail Server 0.51.3135 CVE-2021-43459 CVE-2021-43461 CVE-2021-43462
- Presentation Hacking From the Sky - Building a Penetration Testing UAV prototype
- @Miner Automated Vulnerability Discovery in Windows Applications - 12 CVEs
- Resource Efficient Internal Network Honeypots (Homelab)
- Microsoft security researcher acknowledgment May 31, 2021
- Windows Memory-Injected Malware Detection Freeware Comparison
- Applied Purple Teaming Series ( Attack, Detect, & Defend ) Part 3
- DHCP Starvation & DHCP Spoofing attacks On Cisco Network Switches (Infrastructure Security)
- Applied Purple Teaming Series ( Weaponize Windows ) Part 2
- Quick and Dirty Reconnaissance and Vulnerability Scanning Tool
- Playbook that randomly selects malware and deploys it to add a layer of difficulty when practicing IR & Threat Hunting (Blue-Team)
- Applied Purple Teaming Series ( The Virtual Environment ) Part 1
- Studying Sysmon's Ability to Detect Process Injections Using Different Configuration Schemas
- Traccar GPS Tracking System service path vulnerability CVE-2021-21292
- Ansible playbook designed to configure and deploy rsyslog, Wazuh, Kolide Fleet launcher, OSquery, and Winlogbeat for Windows and Linux (Blue-Team)
- "It's ours now" is a C# tool that collects unpacked/downloaded files using Windows event handlers (Malware-analysis)
- Unquoted service path on Veyon Microsoft Windows LPE CVE-2020-15261
- RosarioSIS < 6.5.1 Reflected Cross-Site Scripting CVE-2020-13278
- rConfig Network Device Configuration Management 3.9.5 RCE CVE-2020-15715
- rConfig Network Device Configuration Management 3.9.5 SQLi CVE-2020-15714, CVE-2020-15713
- rConfig Network Device Configuration Management 3.9.5 LFI CVE-2020-15712
- RosarioSIS 6.7.2 Reflected Cross-Site Scripting CVE-2020-15718, CVE-2020-15717, CVE-2020-15716, CVE-2020-15721
- Machine Learning Approach to Guess Passwords via Microphones Write-up & PoC (Red-Team)
- Admidio version 3.3.13 Unauthenticated SQLi CVE-2020-11004
- CellTower is credentials, events, and any data logging tool QSearchSploit (Red-Team)
- Malicious patch for Pfsense router to perform Red Team activities Bfsense (Red-Team)
- Leantime management system < 2.0.15 BSQL Injection CVE-2020-5292
- Scalable infrastructures for Red/Blue/Gray-Team themed competitions Stateless (IaC)
- Google Chrome Extension Automates Testing Fundamental Web Problems (Pentesting)
- Processes To Watch For Unwanted & Unexpected Blue Team Actions Windows Persistence (Red-Team)
- In-memory implant that uses C# techniques to bypasses Windows Firewall and Defender C2 (Red-Team)
- 2019 End-of-Year Infrastructure Upgrades
- Developing Use Cases That Nefariously Utilize Twitter's API For The Purpose of Building Covert Communications Talk & Paper (Red-Team)
- Hidden in Plain Sight: Developing Use Cases That Nefariously Utilize Twitter’s API For The Purpose of Building Covert Communications
- Post-exploitation C2 that targets browsers Write-up & tool (Red-Team)
- Integrated Windows rootkit projects and persistence techniques Nemo (Red-Team)
- Integrating C3 With Cobalt Strike via ExternalC2 And Studying Their Behavior
- Information theft through covert channel by exploiting HTTP Post method (PoC)
- Malicious process monitors and infects specific kinds of files (Red-Team)
- Preparation material to prepare for AWAE course (Resources)
- PWNDashboard, Engagements and competitions dashboard (Red-Team)
- BlueDucky, Creates a list of USB-Rubber-Ducky instructions (Blue-Team)
- Clearview, Web Application Challenge (Education)
- A Golden Image for Our Pentest VMs
- Ansible playbook to customize Kali Linux Kai-TX (Tool)
- Customizing Searchsploit outputs from Kali Linux QSearchSploit (Tool)
- Windows Exploit Development: Egg Hunting
- Windows Exploit Development: Unicode and Venetian shellcode techniques
- Detecting Bugs Using Network Protocol Fuzzing
- Exploit Development: Utilizing imported functions
- Exploit Development: Manually Encode Bytes & Shellcode Carving
- TorMultiplier creates multiple Tor sockets PoC
- C2 project controls a self-propagating MS17-010 worm M-Botnet (Red-Team)
- Simple CLI web Intruder that uses Netcat