
cve-2022-1471-jira-lab
Offline CVE-2022-1471 lab: SnakeYAML unsafe deserialization to RCE; compares vulnerable 1.x vs fixed 2.x using a harmless local payload.

Offline CVE-2022-1471 lab: SnakeYAML unsafe deserialization to RCE; compares vulnerable 1.x vs fixed 2.x using a harmless local payload.

Host and manage multiple Juice Shop instances for security trainings and Capture The Flags

Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.


End-to-end simulation of detecting a root-less Android Drop Device (Casper) using Wazuh SIEM to capture Layer 7 attacks like Shellshock…

[First-Blood-XO] React Server Component endpoint vulnerable to CVE-2025-55182 (RCE) → enumerated SUID binaries → /usr/bin/perl had SUID set → used…

Archived CTF challenge sources and deployable sandboxes since 2017, with intentionally vulnerable exercises for hands-on security training and…

A hands-on project demonstrating the setup of virtual security lab, network reconnaissance, and exploitation of CVE-2012-1823.

analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits


Python3 script that can be used to demonstrate **CVE-2025-55182**. It exploits a server-side JavaScript injection vulnerability in Next.js/React…

Docker container to setup a vulnerable elfinder version on both nginx and apache servers. Can be used to test vulnerability POC

Detection, Exploit and Mitigation for CVE 2023 46604.


Active Directory Lab for Penetration Testing

Moment.js vuln lab