
EntraGoat
A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.


Comprehensive self-paced manual on Windows identity, Kerberos, and PKI internals, covering credential dumping, ticket forgery, domain persistence,…


Demos for the Blackhat USA 2022 talk "Taking Kerberos to the Next Level"

CVE-2024-38200 & CVE-2024-43609 - Microsoft Office NTLMv2 Disclosure Vulnerability

Proof-of-concept exploit for PaperCut CVE-2023-27350, chaining authentication bypass with built-in scripting abuse to achieve remote code execution…

CentOS Control Web Panel, Root Privilege Escalation

POC for CVE-2025-54918 and a technical demonstration.


Dahua IP camera CVE research toolkit (CVE-2021-33044/33045, CVE-2025-31700/31701)

ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the…

This is poc of CVE-2022-46169 authentication bypass and remote code execution

CVE-2022-39227 : Proof of Concept

Authentication Bypass Vulnerability — CVE-2024–4358 — Telerik Report Server 2024

Modular PoC for CVE-2025-58434 (account takeover) and CVE-2025-59528 (RCE) in Flowise. Automates the full attack chain from unauthenticated token…

SimpleHelp OIDC Authentication Bypass PoC

The Demo for CVE-2017-11427