#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

Intentionally vulnerable VM-hosted Java shop — Log4Shell (CVE-2021-44228) workshop lab (EC2 / Azure VM / GCE)

A cybersecurity case study analysing CVE-2023-20198 in Cisco IOS XE, covering vulnerability exploitation, mitigation strategies, secure software…

Hands-on lab environment for reproducing CVE-2025-55182, providing setup instructions and notes for security researchers to analyze and understand…

SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated…

A fun activity using a packet capture file from the log4j exploit (CVE-2021-44228)

Bash script for Privilege Escalation via "ndsudo" (Netdata Local Exploit)

Working exploit for CVE-2025-23167 – HTTP request smuggling in vulnerable Node.js 20.x versions before 20.19.2

SOC lab exercise for analyzing and responding to Palo Alto Networks PAN-OS command injection vulnerability (CVE-2024-3400) with step-by-step incident…

Berisi 2 program C dari exploitDB untuk melakukan privillage eskalation untuk ubuntu 16.04

The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The…

Struts 2 web app that is vulnerable to CVE-2017-98505 and CVE-2017-5638

Educational demonstration of CVE-2017-5123 kernel exploit, ICMP-based rootkit command-and-control, and OS command injection vulnerable web…

Full-chain reproduction of CVE-2022-36804 (Bitbucket RCE). Includes a Dockerized laboratory, pspy64 monitoring for null-byte injection verification,…

Proof-of-concept exploit for CVE-2024-21413 using Moniker Link in HTML email to trigger SMB connection and capture netNTLMv2 hashes via Responder.…

Lab environment and PoC exploit for CVE-2025-55182 (React2Shell), a critical RCE vulnerability in React Server Components. Includes vulnerable app,…

Docker-based test lab for CVE-2025-55182 (React2Shell) RCE vulnerability in React 19.1.0/Next.js 15.1.0. Includes exploit scripts, WAF bypass testing…

Target Code + Exploit

ingress-nginx admission controller RCE escalation PoC