#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

信呼 v2.3.2 针对CVE-2023-1773的研究环境
A list of resources for those interested in getting started in bug bounties

Step-by-step analysis and exploitation lab for Drupal CVE-2018-7600 remote code execution vulnerability, including debugging, exploit code, and…

CVE-2021-44228

Dockerized environment to test pentest tools against CVE-2018-15473. Simple setup with docker-compose for vulnerability exploitation practice.

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

Educational exploit implementation for CVE-2007-2447 Samba 3.0.20-3.0.25rc username map script command execution vulnerability with Python SMB client…

Go-based exploit for CVE-2018-6574, designed as a pentesterlab exercise to practice binary exploitation and vulnerability analysis.

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) that automates LDAP and HTTP servers to deliver a reverse shell payload to a vulnerable Java…

Workshop materials for mastering WinDbg debugging in kernel and user mode, with KdNet setup, demos, and a Time Travel Debugging challenge for binary…

A curated list of hacking environments where you can train your cyber skills legally and safely

Materials for Windows Malware Analysis training (volume 1)

Step-by-step analysis and lab setup for CVE-2023-39361, an unauthenticated SQL injection in Cacti v1.2.24, with exploitation and mitigation…

Educational demo of a Server-Side Request Forgery (SSRF) vulnerability in Next.js (CVE-2024-34351), with step-by-step exploitation and mitigation…

Local Privilege Escalation (LPE) vulnerability in Polkit - Pwnkit

Slides and files for the Reversing Rust Binaries: One step beyond strings workshop at REcon 2024, presented on June 28, 2024.

Create lab for CVE-2024-4577

This is an Incident Response Walkthrough: Mitigating a Zero-Day Attack (CVE-2024-4577)