
CVE-2024-23897
Docker-based lab and exploit script for CVE-2024-23897, a critical arbitrary file read in Jenkins CLI via args4j expandAtFiles, with steps to chain…

Docker-based lab and exploit script for CVE-2024-23897, a critical arbitrary file read in Jenkins CLI via args4j expandAtFiles, with steps to chain…

An empirical security testbed evaluating prompt injection, confused-deputy vulnerabilities, and tool-calling defenses in LLM agents.

Educational lab demonstrating CVE-2025-6218 path traversal in WinRAR. Includes a malicious RAR file and step-by-step guide to observe file overwrite…

Local Docker lab demonstrating CVE-2026-5718 arbitrary file upload in a WordPress plugin, with vulnerable and patched services for side-by-side…

PoC CVE-2023-29386 — Manager for Icomoon < 2.1 - Unauthenticated Arbitrary File Upload

The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the…

CVE-2021-3129: Laravel Debug Mode RCE - Complete exploitation lab with Python exploit, Docker container, and security analysis guide.

Code Roulette is a terminal interface based (TUI), online multiplayer, Russian Roulette game where the loser executes the winner's Python payload…

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…


Public technical advisory and reproduction evidence for CVE-2026-52134 affecting GOOSE replay handling in libiec61850 v1.6.

Tools and Techniques for Blue Team / Incident Response

PoC for CVE-2026-66066 in Ruby on Rails

Proof-of-concept exploit for CVE-2026-54806: unauthenticated PHP object injection in WP Activity Log plugin enabling blind RCE via User-Agent header.…

An example C program which contains vulnerable code for common types of vulnerabilities. It can be used to show fuzzing concepts.

Proof-of-concept exploit for CVE-2024-4040, demonstrating unauthenticated SSTI and local file read in CrushFTP, with Docker lab and mitigation…

Free, offline SOC Analyst Hub for Tier 1 — IR checklists, alert triage playbooks, threat hunting queries & analyst onboarding. Single HTML file, no…

Proof-of-concept exploit for CVE-2026-31431 (Copy Fail), a Linux kernel LPE via algif_aead page-cache corruption, with detection, lab, and mitigation…