#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

Useful Techniques, Tactics, and Procedures for red teamers and defenders, alike!

A vulnerable version of Rails that follows the OWASP Top 10

right payload for java CVE

Docker lab for reproducing CVE-2025-11262, an unauthenticated stored blind XSS in Link Whisper Free WordPress plugin. Includes vulnerable and patched…

A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific…

An autonomous red-teaming engine for LLMs. RedThread manages the full security lifecycle: generating adversarial attacks, executing precision…

A revamped and updated version of my original OneRuleToRuleThemAll hashcat rule

An intentionally designed broken web application based on REST API.

Staged DLL injection proof-of-concept built in C using Win32 APIs — developed in an isolated lab environment for red team certification study (CRTO).

Docker-based lab environment and exploit for CVE-2019-7609 (Kibana Timelion RCE) with reverse shell payload and patch analysis.

Source code for the Binaries of OWASP WrongSecrets

Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a…

A curated list of Web3 Security materials and resources for Pentesters and Bug Hunters.

A collection of challenge based hack-a-thons including student guide, coach guide, lecture presentations, sample/instructional code and templates. …

"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events.…

Intentionally vulnerable Spring app to test CVE-2022-22965


Exploiting Bluekeep (CVE-2019-0708) on windows 7 using metasploit (Esucational lab)