
Why-so-Serious-SAM
PoC malware that uses exploit CVE-2021-36934 (improper ACLs on shadow copies) using a fileless red team method on Windows 10/11 with LOLBins,…

PoC malware that uses exploit CVE-2021-36934 (improper ACLs on shadow copies) using a fileless red team method on Windows 10/11 with LOLBins,…

Re-play Security Events

Time-Based Blind SQL Injection tool for MySQL - CVE-2019-9053

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.

⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡


CS50 Cybersecurity final project — Palo Alto OAuth token breach (CVE-2024-3400)

ARM buffer overflow challenge exploiting NFC tag input on Raspberry Pi. Includes hardware assembly guide, server code, and flag retrieval for CTF and…

CTF team website aggregating writeups and resources for web security challenges including XSS, SQLi, CSRF, SSRF, and XXE.

Docker Compose wrapper to deploy AperiSite, a curated platform hosting CTF writeups, security challenges, and educational resources covering web,…

The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.

OWASP Learning Gateway Project

This project simulates a real-world attack-and-defend scenario across two virtual machines. You will exploit a critical pre-authentication RCE…

A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS,…

The hardware engineering home of the Circuit Crafters first electronic badge project.

This repository provides a detailed walkthrough of the *Solar Exploiting Log4j room* on TryHackMe, focusing on exploiting the critical Log4Shell…