
offensive-one-liners
110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

Educational CVE proof-of-concept repository with lab scripts for reproducing, testing, and analyzing specific vulnerabilities in isolated…

A collection of awesome security hardening guides, tools and other resources

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

Curated collection of offensive security conference slide decks covering kernel and mobile exploitation, VM/container escapes, and…

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting)…

Tracking IPV6_FRAG_ESCAPE (CVE-2026-53362, CVE-2026-53366), the IPv6 fragmentation container escape

Tracking ITScape (CVE-2026-46316), the KVM/arm64 guest-to-host escape

Proof of concept code for Datadog Security Labs referenced exploits.

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

CVE-2026-33634 (CVSS 9.4) — The most impactful CI/CD supply chain attack of 2026 so far.


The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

OWASP Ontology-driven Threat Modelling framework

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security