# Disclaimer & Authorized Use This repository documents a vulnerability that is **fixed by the vendor**. It exists to help defenders understand attacker capability, hunt for it, and remediate correctly. - All testing was performed on **isolated, personally-owned lab hardware and accounts**, against a build intentionally left unpatched for the exercise. - The scripts are provided **for authorized defensive research, detection engineering, and education only**. Running them against systems you do not own and have explicit written authorization to test may be illegal. - No warranty. The authors accept no liability for misuse. - Sensitive lab values (internal hostnames/IPs, callback domains, and especially **machine-key material**) have been redacted. Do not restore or publish real key material. By using anything here you agree to use it lawfully and only where authorized.