
offensive-one-liners
110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

CVE-2026-31431 Copy Fail — Linux kernel LPE tester via MCP

Kestra Unauthenticated RCE Exploit (CVE-2026-53576)

Fawkes is a golang Mythic C2 Agent exclusively written by AI.

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…


Linux LPE - Reliable Jail/Container Escape

Live cryptojacking toolkit with CVE-2026-31431 LPE exploit, container escape, kernel rootkit, and XMRig Monero miner, captured from real attacks for…

PHP poc, exploit for CVE-2025-9074

PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers.…

📦 Make security testing of K8s, Docker, and Containerd easier.

Hack The Box - Silentium machine writeup | CVE-2025-58434, CVE-2025-59528, CVE-2025-8110

A collection of manifests that will create pods with elevated privileges.

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

* React2Shell-CVE-2025-55182

* React2Shell-CVE-2025-55182