
security-operations-labs
Threat Modeling, IT-/OT-Segmentierung, Snort Detection und reproduzierbare Validierung eines Drupal-Detection-Profils.

Threat Modeling, IT-/OT-Segmentierung, Snort Detection und reproduzierbare Validierung eines Drupal-Detection-Profils.

patch-manager

Centralized Wazuh SCA Assessment for CVE-2026-42945 on NGINX Servers

SonicWall security audit toolkit with vulnerable CTF lab (CVE-2021-20038, CVE-2024-53704)

CVE-1999-0678- /doc directory browsable

Linux kernel CVE exploit analysis report and relative debug environment. You don't need to compile Linux kernel and configure your environment…

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

Proof-of-concept exploit for CVE-2026-29923, a BYOVD privilege escalation in pstrip64.sys. Demonstrates physical memory read/write via IOCTL to steal…

Vulnerability in HTTP Protocol Stack Enabling Remote Code Execution and Potential System Crash.

End-to-end Domain Controller exploitation using Metasploit and Impacket: discovered DC10, exploited Zerologon (CVE-2020-1472), extracted NTLM hashes,…

Educational lab demonstrating EFS bypass (CVE-2021-43217) on Windows 10 using Kali Linux, Metasploit, and custom Python shellcode for penetration…

A collection of links related to Linux kernel security and exploitation

This is an Incident Response Walkthrough: Mitigating a Zero-Day Attack (CVE-2024-4577)

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Proof-of-concept exploit for CVE-2026-31431 (Copy-Fail), a Linux kernel AF_ALG and splice() flaw enabling page cache poisoning and local privilege…

Modular framework for researching and exploiting a Linux kernel privilege escalation vulnerability using AF_ALG and page cache injection to modify…

Exploitation of CVE-2023-44604. Using a Kali Linux VM (attacker) and a Debian 11 server VM (victim)

Hands-on lab for exploiting and understanding Log4Shell (CVE-2021-44228) using Docker, Kali Linux, Burp Suite and log4j-shell-poc. For teaching and…