
Triage-CVE-2017-0144
Goal is to triage well known attacks and learn how security teams quickly respond.

Goal is to triage well known attacks and learn how security teams quickly respond.

Ansible role that simulates a realistic CrushFTP CVE-2025-31161 exploitation scenario with rotating sensitive data files and automated defender…

System Vulnerability Checklist & Network Security Hardening project featuring reconnaissance, vsFTPd backdoor analysis (CVE-2011-2523), and active…

Advanced Multi-Technology Stress Testing Framework Educational Cybersecurity Tool for High-Performance Network Testing

Open-source interactive security awareness training library with 130+ SCORM exercises covering phishing, vishing, BEC, MFA fatigue, and OWASP AI/LLM…

PoC and test server

Unofficial libvirt patch for the free SpecterOps Kubernetes for Red Teamers lab

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Proof-of-concept exploit for CVE-2020-13925, a command injection vulnerability in Apache Kylin's diagnostic API, allowing remote code execution via…

Curated collection of cybersecurity resources, labs, and training materials covering ethical hacking, penetration testing, exploit development,…

The vulnerable application that will teach you how to hack WebSockets

CVE-2025-26794: Blind SQL injection in Exim 4.98 (SQLite DBM)- exploit writeup

An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed…

Docker-based lab and exploit script for CVE-2024-23897, a critical arbitrary file read in Jenkins CLI via args4j expandAtFiles, with steps to chain…

OSCP field notebook: merged technique vault and numbered notes. MIT.

Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

Proof-of-concept exploit and detailed analysis of CVE-2022-0847 (Dirty Pipe) Linux kernel privilege escalation vulnerability, including Docker…

A benchmark for LLM-driven bug discovery: 77 challenges across 43 open-source projects (C/C++/Java).