
ctf-cve-2019-11043
Intentionally vulnerable PHP app with Nginx/PHP-FPM setup for reproducing CVE-2019-11043, including Docker and Kubernetes deployment,…

Intentionally vulnerable PHP app with Nginx/PHP-FPM setup for reproducing CVE-2019-11043, including Docker and Kubernetes deployment,…

Zero-code K8s sidecar for log sanitization. Detects secrets via Entropy Analysis, preserves JSON integrity, and redacts PII deterministically. 🛡️

An egress firewall for untrusted workloads.

PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

A container image that exfiltrates the underlying container runtime to a remote server

3 linux kernel bugs chains to do secure comm app using side channel to establish key and establish covert channe;

AI coding agents that can't exfiltrate secrets or merge their own PRs.

An open-source framework for detecting, redacting, masking, and anonymizing sensitive data (PII) across text, images, and structured data. Supports…

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Proof-of-concept exploit for CVE-2026-78122, demonstrating container filesystem and environment variable exfiltration through docker-socket-proxy's…

PoC exploit for CVE-2026-21002 serverless cold-start credential leakage, demonstrating how reused Lambda /tmp directories expose AWS secrets to other…

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

A collection of AWS penetration testing junk

Open-source IoT Platform - Device management, data collection, processing and visualization.