
kubernetes-goat
Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

A secure low code deception runtime framework, leveraging AI for System Virtualization.

Semi-automated network penetration testing framework with integrated NMAP, Hydra, Nikto, and CVE-to-exploit mapping for discovery, reconnaissance,…

Multi-architecture Docker toolkit for penetration testing with preconfigured tools for web, network, mobile, API, OSINT, and forensics. Features…

Docker-based Shellshock (CVE-2014-6271) exploit environment with ready-to-use attack scripts for CGI, SSH, and DHCP vectors. Includes vulnerable Bash…

Docker-based playground for testing CVE-2021-41773, demonstrating local file disclosure and remote code execution in Apache HTTPd 2.4.49.

Dockerized proof-of-concept for CVE-2022-42889 (Text4Shell) with script, DNS, and URL lookup-based RCE payloads for security testing and education.

Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster

Provides vulnerable Docker images for CVE-2021-41773 (Apache path traversal) with PoCs for file read and RCE, enabling security testing and practice.

Proof-of-concept exploit for CVE-2021-40438 (Apache mod_proxy SSRF) with Docker-based vulnerable environment for testing and validation.

Dockerized vulnerable environment for CVE-2018-11776 with proof-of-concept exploits, enabling hands-on testing of Apache Struts2 remote code…

Hands-on lab environment for testing Apache Tomcat unauthenticated RCE (CVE-2025-24813) with Docker setup and step-by-step exploitation guide.

PoC exploit for CVE-2025-32375 targeting BentoML 1.4.7, with a Docker-based vulnerable environment for testing and verification of the remote code…

Dockerized proof-of-concept exploit for CVE-2018-11776 (Apache Struts2) with a Go-based command execution payload for penetration testing and…

A containerized testing environment for CVE-2025-55182, a critical (10.0 CVSS) Remote Code Execution vulnerability in React Server Components.

Docker-based vulnerable environment for CVE-2017-8046 Spring framework remote code execution exploit, part of the Cved vulnerable container…

Educational proof-of-concept exploit for CVE-2025-55182 targeting a React application, with Docker Compose environment for local testing and security…

Isolated research lab and proof-of-concept for validating a SharePoint deserialization vulnerability (CVE-2025-53770) with a Python exploit driver,…