
railsgoat
A vulnerable version of Rails that follows the OWASP Top 10

A vulnerable version of Rails that follows the OWASP Top 10

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

Cryptanalysis golf: break schemes and prove it in Lean 4. Proof-of-concept board.

Re-play Security Events

CTF Cheat Sheet + Writeups / Files for some of the Security CTFs that I've done

Ansible role that simulates a realistic CrushFTP CVE-2025-31161 exploitation scenario with rotating sensitive data files and automated defender…

SQLPad - Template injection (POC exploit for SQLPad RCE [CVE-2022-0944])

Automated steganalysis platform that detects hidden data in images using 16 parallel analyzers, bit-layer visualization, and an in-app wiki for CTF…

The RF and reverse engineering framework for everyone. Follow and ★ to show your support!


Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

Local Linux enumeration script that identifies privilege escalation vectors including misconfigurations, world-writable files, clear-text passwords,…

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡

Go package that aids in binary analysis and exploitation

Proof-of-concept exploit for CVE-2025-62215, a Windows kernel Use-After-Free vulnerability in SepTokenSidSharingEnabled. Includes a kernel driver and…

Automated JWT security testing tool that exploits known CVEs, tampers with payloads, performs JKU/X5U injection, key confusion attacks, and verifies…

A curated list of AI Security materials and resources for Pentesters, Bug Hunters, and Security Researchers.