#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

Practice POC scripting in Tryhackme’s intro poc scripting room (For Linux)

Step-by-step lab guide for simulating, detecting, and mitigating the Zerologon vulnerability (CVE-2020-1472) on Windows Server 2016 using Kali Linux…

Instructions for exploiting vulnerabilities CVE-2021-44228 and CVE-2023-46604

A simple python script for a firewall rule that blocks incoming requests based on the Spring4Shell (CVE-2022-22965) vulnerability

A proof of concept of the path traversal vulnerability in the python AioHTTP library =< 3.9.1

Docker-based lab for practicing WordPress CVE-2024-1071 exploitation with automated PoC scripts and step-by-step setup instructions.

This is a potentially vulnerable Java web application containing Log4j affected by log4shell(CVE-2021-44228).

Scanner for CVE-2024-23897 - Jenkins

CVE-2024-21413 PoC for THM Lab

Simple Java Front and Back end with bad log4j version featuring CVE-2021-44228

CVE-2024-1071 with Docker

This is a resource factory for anyone looking forward to starting bug hunting and would require guidance as a beginner.

DEFCON 30 Mainframe buffer overlow workshop container

Proof-of-concept exploit for CVE-2023-39362, an authenticated command injection in Cacti's SNMP options. Includes a vulnerable Docker environment for…

Emulates realistic user behavior in Active Directory lab environments for red and blue team tradecraft development. Generates random benign user…

Educational proof-of-concept for the DNSSEC KeyTrap vulnerability (CVE-2023-50387) with a Docker-based lab environment to demonstrate algorithmic…

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.

Educational PDF files demonstrating client-side exploitation techniques, including calculator execution and directory browsing, for security testing…