




A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific…

NOTICE This repository contains the public FTC SDK for the SKYSTONE (2019-2020) competition season. If you are looking for the current season's FTC…

Bash-based Linux persistence detection tool for DFIR investigations. Scans 15+ persistence mechanisms (systemd, cron, kernel modules, SSH,…

Multi-cloud vulnerable-by-design deployment tool using Terraform to provision intentionally insecure cloud infrastructure for security training and…

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.



A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk

OSINT tool researched and designed to hunt down IG handles

FortiGate CVE-2022-40684 assessment tool for user enumeration, configuration dump, and lab testing.

BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is…

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

Generates pseudo-malicious files from YARA rules to trigger AV/EDR detection, enabling malware research, rule QA, and network sensor pressure testing…
