
PolyEngine
PolyEngine is an evasive PE packer designed for CTF challenges and low-level Windows security education. It focuses on bypassing EDR and AV…

PolyEngine is an evasive PE packer designed for CTF challenges and low-level Windows security education. It focuses on bypassing EDR and AV…

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

This repository provides a centralized resource for operational cyber defense and offense, compiling Theory, Tools, Operating Procedures, and…

helps visualize heap operations for pwn and debugging

Web application with vulnerabilities found in real cases, both in pentests and in Bug Bounty programs.

A Highly Accessible and Automated Virtualization Platform for Security Education

Discover hidden debugging parameters and uncover web application secrets

Collection of penetration testing tools

CPH:SEC WAES: Web Auto Enum & Scanner - Auto enums website(s) and dumps files as result

Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

Binary Exploitation and Reverse-Engineering (from assembly into C)

Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.


This tool aims at automating the identification of potential service running behind ports identified manually either through manual scan or services…

Search and extract blob files on the Ethereum Blockchain network

Walk x86-64 page tables by hand in qemu and gdb. Decompose a virtual address, follow cr3 through all levels of physical memory, and extract a flag…

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…