Skip to content

Security: JMarchiori13/cred-harvester

Security

SECURITY.md

Security Policy

Scope

This repository is a documentation-only security research scaffold: research notes, lab setup guides, and module plans for authorized, isolated-lab study of credential access techniques (MITRE ATT&CK TA0006).

  • Research and education only. Nothing here is intended for use against systems you do not own or lack explicit written authorization to test.
  • Authorized lab use only. All experiments must run in the isolated environment described in lab/setup.md, with fictitious credentials.
  • Unauthorized use of the techniques documented here may be a crime (Brazil — Lei nº 12.737/2012; United States — CFAA; equivalent legislation elsewhere).

Supported versions

This is a docs-only project; there are no versioned releases and no runnable production code to patch. The main branch always reflects the current state of the research notes.

Reporting a concern

If you believe content in this repository is unsafe, inaccurate in a way that creates risk, or violates the responsible-use scope above:

  1. Open an issue in this repository describing the concern.
  2. Do not include real credentials, dumps, or third-party data in the report.

Content concerns are triaged by the repository owner and addressed by correcting or removing the material in question.

There aren't any published security advisories