
reverse-shell-generator
Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

An open-source user mode debugger for Windows. Optimized for reverse engineering and malware analysis.

An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed…

AI agent framework for black-box security testing with autonomous multi-agent orchestration, built-in pentesting tools, and MCP integration for bug…

How to write a CrackMe for a CTF competition. Source code, technical explanation, anti-debugging and anti reverse-engineering tricks.

A vulnerable version of Rails that follows the OWASP Top 10

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific…

Cryptanalysis golf: break schemes and prove it in Lean 4. Proof-of-concept board.

A list of Capture The Flag (CTF) frameworks, libraries, resources and software for started/experienced CTF players 🚩

Deliberately vulnerable GitHub repository configured with CVE-2021-32724 for practicing exploitation of the Check Spelling Workflow in a controlled…

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…