Tools

Most of these exist because I needed the answer on an engagement and nothing gave it to me. The newer ones share a rule: measure what a credential, agent, or network can reach, and never widen it in the process. Last-commit dates come from GitHub at build time.

Agents and credentials

Networks and applications

Contributions and disclosures

Merged pull requests to Sliver, Metasploit (the Jenkins credential gather module), and Hashcat.

A few CVEs, including a command injection in Adobe Acrobat Reader (CVE-2021-28634) and an Informacast JMX misconfiguration that gave remote code execution.