
ludus_crushftp_cve-2025-31161_sim
Ansible role that simulates a realistic CrushFTP CVE-2025-31161 exploitation scenario with rotating sensitive data files and automated defender…

Ansible role that simulates a realistic CrushFTP CVE-2025-31161 exploitation scenario with rotating sensitive data files and automated defender…

Open-source interactive security awareness training library with 130+ SCORM exercises covering phishing, vishing, BEC, MFA fatigue, and OWASP AI/LLM…

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners.…

Hands-on workshop for learning Android kernel vulnerability analysis and exploitation, with Docker-based build environment and practical exercises.

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

A benchmark for LLM-driven bug discovery: 77 challenges across 43 open-source projects (C/C++/Java).

Collection of intentionally insecure iOS and Android apps for learning mobile security testing, reverse engineering, and vulnerability analysis,…

Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

A complete Blue Team Cybersecurity Lab featuring pfSense, Suricata, and ELK Stack for network monitoring and threat detection.

A vulnerable version of Rails that follows the OWASP Top 10

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

PoC for CVE-2026-66066 in Ruby on Rails

A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific…

An intentionally designed broken web application based on REST API.

A Proof of Concept for the CVE-2021-46398 flaw exploitation

Exploiting Bluekeep (CVE-2019-0708) on windows 7 using metasploit (Esucational lab)