#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

Kestrel threat hunting language: building reusable, composable, and shareable huntflows across different data sources and threat intel.

d

A proof of concept of traefik CVE to understand the impact

Bash POC for CVE-2020-9484 that i used in tryhackme challenge

YISF 2024 CTF-Web (Directory Traversal via ".tar" file, CVE-2007-4559), easy

Kurukshetra - A framework for teaching secure coding by means of interactive problem solving.

Intentionally vulnerable web application for security training, CTF competitions, and testing security tools. Covers OWASP Top Ten vulnerabilities…

Docker-based lab environment to simulate and exploit CVE-2019-9978, a remote code execution vulnerability in WordPress Social Warfare plugin versions…

Exploit a 2021 Kernel vulnerability in Ubuntu to become root almost instantly!

🚨 Just completed an incident report on Event ID 217: Apache OFBiz Auth Bypass and Code Injection 0-Day (CVE-2023-51467). This critical vulnerability…

🚨 New Incident Report Completed! 🚨 Just wrapped up "Event ID 268: SOC292 - Possible PHP Injection Detected (CVE-2024-4577)" on LetsDefend.io. This…

A small go harness that uses Ollama to orchestrate LLMs in a restricted process flow

Proof-of-Concept for CVE-2024-7856

Module written in Ruby with the objective of exploiting vulnerabilities CVE-2023-2728 and CVE-2024-3177, both related to the secret mount policy in a…

This framework enables user to discover JOP gagdets and can automate building a complete JOP chain to bypass DEP. JOP ROCKET is the ultimate solution…

CVE-2019-19470 exploit replication with source code, WinDbg commands, PEB modification, and decompilation examples for educational red team training.

Defcon 32 Workshop setup and info

POC & Lab For CVE-2021-41773