
Bug-Bounty-Beginner-Roadmap
This is a resource factory for anyone looking forward to starting bug hunting and would require guidance as a beginner.

This is a resource factory for anyone looking forward to starting bug hunting and would require guidance as a beginner.

Vulnerable app with examples showing how to not use secrets

AI Red Teaming playground labs to run AI Red Teaming trainings including infrastructure.

The RF and reverse engineering framework for everyone. Follow and ★ to show your support!

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

A collection of links related to VMware escape exploits

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

:cherry_blossom: Interactive shellcoding environment to easily craft shellcodes

MCP to help Defenders Detection Engineer Harder and Smarter

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

Curated reference for Android forensic artifacts and log paths, with links to CTF writeups, research papers, and mobile device analysis tooling.

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

A compact guide to network pivoting for penetration testings / CTF challenges.

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.

A happy heap editor to support your exploitation process :slightly_smiling_face:

An open source Android application that is intentionally vulnerable so as to act as a learning platform for Android application security beginners.

[漏洞复现] 全球首款单文件利用 CVE-2023-4357 Chrome XXE 漏洞 EXP, 实现对访客者本地文件窃取. Chrome XXE vulnerability EXP, allowing attackers to obtain local files of visitors.