
Triage-CVE-2017-0144
Goal is to triage well known attacks and learn how security teams quickly respond.

Goal is to triage well known attacks and learn how security teams quickly respond.

itunesstored & bookassetd sbx escape

Demonstration of Abusing the Vulnerable driver AmdTools64.sys for Physical R/W.

Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

The vulnerable application that will teach you how to hack WebSockets

How to write a CrackMe for a CTF competition. Source code, technical explanation, anti-debugging and anti reverse-engineering tricks.

Research project reverse-engineering Windows Security Center COM interfaces to trace AV registration through ATL, vtable, WSCAPI, and RPC, with…

A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.

YC (S26) | Open Computer History | Record your screen continuously locally and provide context to your agents (Claude, Codex, Openclaw, Hermes,…

CVE-2025-54100 (CVSS 7.8 High) is a command injection vulnerability in the Invoke-WebRequest cmdlet of Windows PowerShell 5.1. It arises from…

A cybersecurity research game measuring how humans detect AI-generated phishing emails. Built as a retro terminal experience.

PoC exposing a critical IndexedDB vulnerability that enables a disk flooding attack by exploiting the lack of restrictions.

Educational analysis and proof-of-concept code for CVE-2021-4034 (pkexec local privilege escalation), with detailed comments explaining the…

Proof-of-concept exploit for CVE-2024-2961, leveraging iconv encoding flaws and PHP filter chains to read arbitrary files from vulnerable servers via…

A list of covert channels and steganography/steganalysis resources (books, papers & tools)

Educational demonstration of CVE-2007-4559 Python tarfile symlink attack with a script showing why os.path.realpath() fails to prevent extraction…

Detailed technical write-up and proof-of-concept exploit for CVE-2023-33733, a remote code execution vulnerability in the Reportlab Python library…