
CDK
📦 Make security testing of K8s, Docker, and Containerd easier.

📦 Make security testing of K8s, Docker, and Containerd easier.

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.

Isolate your big brother apps https://secure-system.gitlab.io/Insular/

C reimplementation of chwoot PoC



Root cuase & Proof Of Code


Container Excape PoC for CVE-2022-0847 "DirtyPipe"

Customizable Linux Persistence Tool for Security Research and Detection Engineering.

⬆️ ☠️ 🔥 Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock

PoC for Dirty COW (CVE-2016-5195)

Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463

CVE-2022-0185

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…