#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

Mellivora is a CTF engine written in PHP

Shellshock exploit + vulnerable environment

A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench,…

Local Privilege Escalation to Root via Sudo chroot in Linux

Circuit Artist is a digital circuit drawing and simulation game.

Deliberately vulnerable web application lab for practicing exploitation of SQLi, XSS, CSRF, SSTI, IDOR, XXE, and 15+ other common web security flaws…

St2-057 Poc Example

Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2…

Workshop on firmware reverse engineering

Structured collection of 500+ Hack The Box machine writeups, 400+ challenge solutions, and interactive learning tools including knowledge graphs,…

A step by step workshop to exploit various vulnerabilities in Node.js and Java applications

Open-source interactive security awareness training library with 130+ SCORM exercises covering phishing, vishing, BEC, MFA fatigue, and OWASP AI/LLM…

CVE-2021-41773 playground

AV/EDR Lab environment setup references to help in Malware development

Practical MSSQL penetration testing cheat sheet covering enumeration, linked-server pivoting, privilege escalation, persistence, and command…

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security


CVE-2025-49844 (RediShell)