#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

Proof-of-concept exploit for CVE-2026-24061, an unauthenticated remote root privilege escalation in inetutils-telnetd via USER environment variable…

CTF challenge focused on sandbox escape via source code review of a JavaScript execution environment, designed for hands-on vulnerability analysis…

Proof-of-concept lab demonstrating command injection in GitHub Actions workflow dispatch (CVE-2026-39866). Runs vulnerable and patched versions…

Educational CSRF vulnerability demonstration with a controlled lab environment, including a proof-of-concept exploit and a fixed version with proper…

CVE-2021-41773 Exploit Lab

Docker-based lab for reproducing CVE-2021-41773 (Apache HTTP Server 2.4.49) through controlled path traversal and file disclosure using a custom…

Proof-of-concept exploit for a WordPress plugin vote-limit bypass using spoofed X-Forwarded-For headers; ships a Docker lab to validate…

Educational lab and proof-of-concept materials for a specific CVE, providing sandboxed scripts and templates for vulnerability research, authorized…

MCP to help Defenders Detection Engineer Harder and Smarter

Generates pseudo-malicious files from YARA rules to trigger AV/EDR detection, enabling malware research, rule QA, and network sensor pressure testing…

Companion labs to "An Exploration of JSON Interoperability Vulnerabilities"

Custom PowerShell module to setup an Active Directory lab environment to practice penetration testing.

Kurukshetra - A framework for teaching secure coding by means of interactive problem solving.

This framework enables user to discover JOP gagdets and can automate building a complete JOP chain to bypass DEP. JOP ROCKET is the ultimate solution…

Python exploit for the CVE-2021-22204 vulnerability in Exiftool

DEFCON 30 Mainframe buffer overlow workshop container


PoC for CVE-2015-6086