
CVE-2025-32023
PoC & Exploit for CVE-2025-32023 / PlaidCTF 2025 "Zerodeo"

PoC & Exploit for CVE-2025-32023 / PlaidCTF 2025 "Zerodeo"

helps visualize heap operations for pwn and debugging

Automated JWT security testing tool that exploits known CVEs, tampers with payloads, performs JKU/X5U injection, key confusion attacks, and verifies…

Fast Steganography bruteforce tool written in Rust useful for CTF's


Crypto tool for pentest and ctf : try to uncipher data using multiple algorithms and block chaining modes. Usefull for a quick check on unknown…

A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine…

Exploit for CVE-2022-29582 targeting Google's Kernel CTF

Offline MGRS navigation + BLE proximity team sync for 2-8 people. No cell service needed. V1.0 through V4.0 roadmap in README.

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.

一个轻量级浏览器抓包与安全分析扩展,在浏览器侧边栏中即可完成抓包、拦截、修改、重放、规则检测与AI辅助分析的完整工作流。(A lightweight browser extension for traffic capture and security analysis, enabling…

A simple HTTP server for delivering and exfiltrating files/data during, for example, CTFs.

Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.


Challenge handouts, source code, and solutions for UofTCTF 2025

This repository contains all lab instructions for the following content: Info Sec Core Skills, SOC Core Skills, ADCD Labs, SOC Analyst Labs, & BnB…

📜 Scrape targeted wordlists for password cracking using CSS selectors