
CVE-2021-25735
Exploit for CVE-2021-25735 demonstrating Kubernetes Validating Admission Webhook bypass via node label manipulation, with deployable Docker container…

Exploit for CVE-2021-25735 demonstrating Kubernetes Validating Admission Webhook bypass via node label manipulation, with deployable Docker container…

Docker-based lab environment to reproduce and exploit CVE-2018-1111 (DynoRoot) with automated attacker and victim scripts for hands-on security…

CLI tool that explains CVEs in plain English and scans repos for impact. Powered by Claude.

Sudo <= 1.8.14 Local Privilege Escalation and vulnerable container

A tool to reverse engineer and inspect the RPM and APT databases to list all the packages along with executables, service, versions and CVE.

Dockerfile and Kubernetes manifests for reproduce CVE-2024-3094

3 linux kernel bugs chains to do secure comm app using side channel to establish key and establish covert channe;

Exploit for Linux kernel CVE-2026-31431 causing page cache corruption via authencesn AEAD manipulation, targeting privilege escalation in containers…

Proof-of-concept and educational report demonstrating local privilege escalation to root via default LXD group membership on Ubuntu Server, with…

Sudo 1.6.x <= 1.6.9p21 and 1.7.x <= 1.7.2p4 Local Privilege Escalation and vulnerable container

PoC for iTerm2 CVEs CVE-2024-38396 and CVE-2024-38395 which allow code execution

Test and validate Log4Shell (CVE-2021-44228) mitigation approaches with a sample vulnerable Log4j app, including JNDI exploitation, environment…

Proof-of-concept exploit for CVE-2025-9074 demonstrating container-to-host file write via exposed Docker Engine API on Windows. For authorized…

Port Scanner with Docker & Prometheus + Grafana integration. A tool for network auditing with multithreading support and real-time monitoring.

Docker Breakout Checker and PoC via CAP_SYS_ADMIN and via user namespaces (CVE-2022-0492)

PoC helper scripts and Dockerfile for CVE-2019-1002101

Zero-trust sandbox for AI agents with kernel-level filesystem jail, transparent network proxy, and YAML-based policy engine to intercept and control…

Hands-on project demonstrating Log4Shell exploitation, detection engineering with Splunk and auditd, and validated remediation in a containerized…