
Lab4PurpleSec
Lab4PurpleSec is a modular Purple Team homelab combining a vulnerable Active Directory environment (GOAD), a Docker-based web DMZ, pfSense +…

Lab4PurpleSec is a modular Purple Team homelab combining a vulnerable Active Directory environment (GOAD), a Docker-based web DMZ, pfSense +…

VMWare vmdir missing access control exploit checker

Low-interaction honeypot that emulates vulnerable network services to capture malware, shellcode, and exploit attempts, with IPv6 and TLS support.

Zeek package detecting CVE-2022-3602 exploitation attempts and vulnerable OpenSSL servers via HTTP Server header and TLS punycode anomalies,…

Zeek script to detect servers vulnerable to CVE-2020-13777

Defensive security demo: seL4 microkernel gateway protecting vulnerable ICS from CVE-2019-14462

Melody is a transparent internet sensor built for threat intelligence. Supports custom tagging rules and vulnerable application simulation.

Wazuh + Suricata SOC lab detecting real exploits (CVE-2011-2523) and brute-force attacks, with custom detection rules for gaps in default IDS…

Educational demo of CVE-2024-21626 runc container escape with eBPF-based detection gadget for exploitation attempts.

CVE-2023-38646

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.
