
Triage-CVE-2017-0144
Goal is to triage well known attacks and learn how security teams quickly respond.

Goal is to triage well known attacks and learn how security teams quickly respond.

Ansible role that simulates a realistic CrushFTP CVE-2025-31161 exploitation scenario with rotating sensitive data files and automated defender…

System Vulnerability Checklist & Network Security Hardening project featuring reconnaissance, vsFTPd backdoor analysis (CVE-2011-2523), and active…

Advanced Multi-Technology Stress Testing Framework Educational Cybersecurity Tool for High-Performance Network Testing

Open-source interactive security awareness training library with 130+ SCORM exercises covering phishing, vishing, BEC, MFA fatigue, and OWASP AI/LLM…

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Unofficial libvirt patch for the free SpecterOps Kubernetes for Red Teamers lab

Proof-of-concept exploit for CVE-2020-13925, a command injection vulnerability in Apache Kylin's diagnostic API, allowing remote code execution via…

The vulnerable application that will teach you how to hack WebSockets

Docker-based lab and exploit script for CVE-2024-23897, a critical arbitrary file read in Jenkins CLI via args4j expandAtFiles, with steps to chain…

A toolset to make a system look as if it was the victim of an APT attack

Practical study notes and walkthroughs for PortSwigger Academy labs, covering web vulnerabilities, payloads, enumeration, and BSCP exam strategies.

A benchmark for LLM-driven bug discovery: 77 challenges across 43 open-source projects (C/C++/Java).

Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

Proof-of-concept exploit and detailed analysis of CVE-2022-0847 (Dirty Pipe) Linux kernel privilege escalation vulnerability, including Docker…

Hands-on lab demonstrating Apache Struts2 OGNL injection (CVE-2017-5638) with step-by-step system analysis, exploitation, sandbox bypass, and…

PoC for CVE-2026-66066 in Ruby on Rails

An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners.…