
poc_CVE-2018-1002105
Proof-of-concept exploit for CVE-2018-1002105 targeting Kubernetes API server. Supports authenticated and unauthenticated privilege escalation to…

Proof-of-concept exploit for CVE-2018-1002105 targeting Kubernetes API server. Supports authenticated and unauthenticated privilege escalation to…

CVE-2021-41773 playground

Scans Docker Hub images using regex patterns to extract exposed secrets, private keys, and authentication tokens for security auditing and incident…

Go-based Kubernetes exploitation tool that scans for exposed ports and exploits cluster misconfigurations, including anonymous Kubelet RCE and etcd…

eBPF-based stealth container that hides processes, sockets, eBPF objects, and audit logs from system monitoring tools, enabling covert…

Docker-based CVE-2018-10933 libssh authentication bypass exploit with patched client for testing SSH server vulnerabilities and unauthorized access…

Making containers more secure with eBPF and Linux Security Modules (LSM)

Linux privilege escalation via LXD

A script used to create a whonix like gateway/workstation environment with docker containers.

CVE-2019-5736 POCs

OpenSSH remote DOS exploit and vulnerable container

Container Snitch checks running processes under the Docker Engine and alerts if any are found to be running as root

Your everyday Linux distribution gone Super Saiyan.

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

Automated container orchestration tool for Browser-in-the-Browser (BITB) phishing attacks, enabling red teams to scale multi-target infrastructure…

Dockerized vulnerable PHP-FPM environment for CVE-2019-11043, with instructions to build and run the phuip-fpizdam exploit to achieve remote code…

POC for CVE-2022-23648

Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock