7-day longest streak
Building realistic offensive capabilities through custom tooling and low-level research. --- About Me I'm a self-taught Security Researcher and Offensive Tool Developer with over 15 years of hands-on experience in…
Building realistic offensive capabilities through custom tooling and low-level research.
---
About Me
I'm a self-taught Security Researcher and Offensive Tool Developer with over 15 years of hands-on experience in cybersecurity. My journey began in the early days of Windows 7 and EternalBlue, where I developed a deep passion for understanding how systems actually work by breaking them.
Currently pursuing a degree in Computer Information Systems - Cybersecurity while maintaining active offensive research. My focus lies in:
- Custom Implant Development and C2 frameworks
- Evasion Techniques (user-mode and kernel-level)
- Memory Injection and Process Hollowing
- Adversary Emulation and Red Team tooling
- Vulnerability Research and Proof-of-Concept development
---
Arsenal & Research Projects
| Project | Description | Tech Stack |
|---------|-------------|------------|
| NGF:Next-Generation-Fetch | An enterprise-grade, OpSec-aware proxy harvesting and validation suite designed for security professionals and researchers. | Python, Proxychains, Docker, Tor |
| vimShark | Interactive terminal-based packet analyzer with vim-like controls, built for efficient network reconnaissance. | Python (Scapy + Urwid) |
| Cruxable | Operational command and intelligence aggregation dashboard. | - |
| Malum | High-performance, modular offensive framework focused on stealth, memory injection, and asynchronous C2 communication. | Rust, Python, C |
| Alien | Modular cross-platform utility engine designed for operation in restricted and monitored environments. | Python |
| Reports | Technical research and threat intelligence notes covering offensive techniques, evasion methods, and vulnerability analysis. | - |
| CVE-2026-6307 | A PoC on V8 Type Confusion in V8 TurboFan (JS-to-Wasm call inlining + FrameState merging) Following the report at: nebusec.ai | JS, Python, YARA |
| CVE-2026-48558 | SimpleHelp OICD Authentication Bypass Leading to RCE | Python |
| CVE-2026-39047 | Epson Printer RAW Protocol Exploit Framework W/ Dry-Runs, Fuzzing, Stageing & Obfuscation | Python |
| CVE-2026-13768 | Gardyn IoT Hub Owner Key Exposure Leading to RCE W/ a C2 Flask server, payload obfuscation, device enumeration & validation. All highly simplified. | Python |
| CVE-2026-58457 | Unauthenticated OS Command Injection in Shenzhen Aitemi M300 Wi-Fi Repeater | Python, Ruby |
| CVE-2026-63030-wp2r00t | A self-contained proof-of-concept for the unauthenticated blind SQL injection reachable through the WordPress REST batch endpoint (/wp-json/batch/v1). Built with weapnoization capabilities | Python |
Additional Tooling:
- Hardened Docker environments for secure offensive operations (
dockerHermes,dockerCode,dockerLLama)
---
Technical Skills
- Languages: C/C++, Rust, Python, JavaScript/Node.js
- Core Areas: Red Teaming, Adversary Simulation, Evasion Research, Implant Development, Memory Forensics
- Tools & Frameworks: Custom C2 development, Process Injection, Linux syscall manipulation, Packet Crafting
- Currently Learning: Advanced EDR bypass techniques, Modern C2 infrastructure design
Currently Working On
- Preparing for OSCP certification
- Expanding evasion capabilities against modern EDR solutions
- Contributing back to the open-source security community
Open to collaboration on interesting offensive security projects, red team tooling, or research opportunities.
Feel free to reach out if you want to discuss fun stuffz on X: @J4ck3LSyN
-
NGF ★ PINNED
An enterprise-grade, OpSec-aware proxy harvesting and validation suite designed for security professionals and researchers. Unlike traditional fetchers, NGF focuses on stealth pivoting, TLS impersonation, and persistent state to provide a high-quality, reliable list of proxies suitable for tools like `proxychains`.
Python ★ 2 1mo agoExplain → -
vimShark ★ PINNED
Is a high-performance, terminal-based network telemetry analyzer and security auditing tool. Engineered for systems administrators, security researchers & autists like myself...
Python ★ 4 1mo agoExplain → -
Reports ★ PINNED
Reports that I gather from research over time for different purposes.
YARA ★ 2 19d agoExplain → -
Malum ★ PINNED
The core arsenal, embodying the essence of calculated malevolence; a convergence of dark precision and control housing tools of digital subversion, from network manipulation to exploitation and beyond — the heart of your security dominion.
Python ★ 2 2mo agoExplain → -
Cruxable ★ PINNED
A Modified version of crucix (https://github.com/calesthio/Crucix.git).
JavaScript ★ 29 2mo agoExplain → -
Alien ★ PINNED
Alien is a long-term development project of mine, I aim to have a all purpose toolkit that can be used in many different situations.
Python ★ 2 5d agoExplain → -
CVE-2026-6307-Longinus
CVE-2026-6307 PoC: Longinus - 2 Boundaries in One Bug https://nebusec.ai/research/v8-cve-2026-6307-writeup/)
Python ★ 10 1mo agoExplain → -
CVE-2026-48558
SimpleHelp OIDC Authentication Bypass PoC
Python ★ 8 1mo agoExplain → -
CVE-2026-63030-wp2r00t
A fully red-team(offensive security) weaponized variant of wp2shell, built for authorized penetration testing & educational purposes.
Python ★ 6 17d agoExplain → -
CVE-2026-39047
Epson Printer RAW Protocol Exploit Framework
Python ★ 6 1mo agoExplain → -
CVE-2026-58457
PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes exploit, validator, payload generator, and Metasploit module. For educational and authorized pentesting only.
Python ★ 2 19d agoExplain → -
CVE-2026-13768
Azure IoT Hub where exposure of an owner-level Shared Access Key enables unauthenticated remote code execution (RCE) against connected IoT devices. Proof-Of-Concept
Python ★ 1 24d agoExplain → -
CVE-2025-53770
Lab & PoC
Python ★ 1 4mo agoExplain → -
dockerLLama
A containerized Ollama and MCP environment with GPU capabilities and CPU fallback.
Dockerfile ★ 1 2mo agoExplain → -
NahamCon2025-CTF-Writeup
The markdown file we used during the CTF. (Truncated Methedology)
Python ★ 1 1y agoExplain → -
PoC-in-GitHub-ATLAS ⑂
Go support the original author! This is only to be implemented alongside A.T.L.A.S
★ 0 1d agoExplain → -
Bael
Once a tool built for Malum, now redesigned in Rust and lethal...
★ 0 4d agoExplain → -
J4ck3LSyN-Gen2
No description.
★ 0 17d agoExplain → -
Claude-Code-awk ⑂
Improvements off the original concept at: https://github.com/brokensec/Claude-Code-awk
Python ★ 0 17d agoExplain → -
crucix-cf ⑂
TUI Based Crucix Expanded - for terminal junkies.
★ 0 1mo agoExplain → -
NGFDB
Storage for NGF proxy index's & databases.
★ 0 1mo agoExplain → -
AUR-PKG-CHECK
No description.
Shell ★ 0 1mo agoExplain → -
dockerHermes
DockerHermit provides a fully containerized, privacy-focused environment for running the [Nous Research Hermes-Agent](https://github.com/NousResearch/hermes-agent). Powered by a local Ollama instance, this setup ensures your agentic workflows remain private while leveraging local GPU acceleration.
Shell ★ 0 1mo agoExplain → -
Hivemind
Possible re-birth of a concept...
★ 0 2mo agoExplain → -
dockerCode
A hardened, containerized development environment based on VS Code (code-server), designed to provide a "Zero Trust" extension sandbox without sacrificing developer velocity.
Dockerfile ★ 0 2mo agoExplain → -
CVE-2026-40369-EXPLOIT ⑂
Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browsers render process sandbox
★ 0 2mo agoExplain → -
pocs ⑂
poc it like it's hot
C ★ 0 2mo agoExplain → -
Remote-DLL--Injection-poc-reverse ⑂
Remote DLL Injection with Timer-based Shellcode Execution
★ 0 1y agoExplain → -
dirtyfrag ⑂
Going to be used in bael for onsite compilation and execution
★ 0 2mo agoExplain → -
claw-code ⑂
A fork of the maps leak... (containerizing & adding better ollama support w/ EDR)
★ 0 4mo agoExplain → -
SecLists ⑂
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
★ 0 4mo agoExplain → -
modern-php-reverse-shell
No description.
PHP ★ 0 4mo agoExplain → -
bruce-firmware ⑂
Predatory ESP32 Firmware | With further functionality.
C++ ★ 0 4mo agoExplain → -
CVE-2025-55182
A simple toolkit to validate, exploit & gain an interactive shell via the react2Shell Next.js RCE.
Python ★ 0 4mo agoExplain → -
logStrikeConceptual
A simple bash script to clean logs, history and journals...
Shell ★ 0 6mo agoExplain → -
TheGame-TryHackMe
A very easy flag, captured the points however.
★ 0 7mo agoExplain → -
cai-reversed ⑂
Cybersecurity AI (CAI), the framework for AI Security
★ 0 8mo agoExplain → -
Discontinued-Dr.Jean
Our Discord Bot (alpha)
Python ★ 0 1y agoExplain → -
MikroTik-MeltDown-The-Sad-Reality-of-IoT-and-Public-WiFi
No description.
★ 0 7mo agoExplain → -
neko-reverse ⑂
A self hosted virtual browser that runs in docker and uses WebRTC. (Backburner project for further possible automation techniques :: PLanned for andras(malum))
★ 0 7mo agoExplain → -
Pyrat-TryHackMe
A minimal & non-disclosing (flags) repo for the TryHackMe room Pyrat
Python ★ 0 7mo agoExplain → -
n8n-CVE-2025-68613-TryHackMe
The minor methodology for room: https://tryhackme.com/room/n8ncve202568613
★ 0 7mo agoExplain → -
dexter-rev ⑂
An autonomous agent for deep financial research (For A.T.L.A.S integration :: Reverse Engineering)
★ 0 7mo agoExplain → -
Advent-Of-Cyber-2025
TryHackMe Advent of Cyber 2025
★ 0 7mo agoExplain → -
RTVPS ⑂
Red Team VPS
Batchfile ★ 0 8mo agoExplain → -
CMSeeK-Reverse-Engineered ⑂
CMS Detection and Exploitation suite - Scan WordPress, Joomla, Drupal and over 180 other CMSs (EDIT: The plan is whiel along side `Worpressscan-Reverse-Engineering` to implement this into Malum and Alien)
★ 0 2y agoExplain → -
Wordpresscan-Reverse-Engineering ⑂
WPScan rewritten in Python + some WPSeku ideas (EDIT: The aim to modularize and modernize this project for my personal implementation into Malum & Alien)
★ 0 5y agoExplain → -
pingSmugglerUpgraded ⑂
An upgraded ability to sneak past firewalls, AV and other detection methods through the use of disguised ICMP pings with ecrptyed payloads, or tunnel communications quitly through the network without any worries.
Python ★ 0 8mo agoExplain → -
Alien-Gen2-Development-History
Old Dev History.
Python ★ 0 8mo agoExplain → -
Suno-Encrypted-Messaging-PoC ⑂
Is that a subversive message in your mid-tier AI Slop or are you just happy to see us?
★ 0 9mo agoExplain → -
Nighly-Malware-Rev
A host for some malware we are reversing
Python ★ 0 1y agoExplain → -
Al13N_Originals ⑂
Bot/Exploitation Developer Enviroment
★ 0 3y agoExplain → -
irc_nfk ⑂
Full-featured Python IRC library for Python.
★ 0 3y agoExplain →
No repos match these filters.