
vucsa
Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover

C++ challenge repository exploring Control Flow Guard (CFG) bypass techniques for Windows binary exploitation research.

IDA 2016 plugin contest winner! Symbolic Execution just one-click away!

Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

Security portfolio of original responsible-disclosure findings, CTF and lab write-ups, methodology notes, and purpose-built pentest tooling covering…

The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation…

Automated Adversary Emulation Platform

Autonomous Hacking Agent for Red Team

AI-driven penetration testing agent that connects to a Kali box, autonomously runs security tools, analyzes results, and iterates through…


Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

Statically-linked ssh server with reverse shell functionality for CTFs and such

exploit for CVE-2026-42945