
digital-forensics-lab
Free hands-on digital forensics labs for students and faculty

Free hands-on digital forensics labs for students and faculty

Proof-of-concept exploit for CVE-2026-4480, an unauthenticated remote command execution in Samba's print subsystem via %J injection. Includes reverse…

A Dockerized setup for running a vulnerable CrushFTP 10 server instance (CVE-2024-4040).

Open-source Windows kernel-level EDR lab for understanding and testing detection methods against process injection, credential dumping, and other…

Hands-on AI security lab platform with 50+ scenarios across prompt injection, agentic system exploitation, model manipulation, and MCP trust boundary…

Proof of Concept for CVE-2025-32463 Local privilege escalation exploit targeting sudo -R on vulnerable Linux systems. For educational and authorized…

Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and…

Research and detection toolkit for Linux kernel LPE CVE-2026-31431, including exploit analysis, YARA rules, auditd/Falco detection, patching guide,…

Research and proof-of-concept for CVE-2022-0185 Linux kernel heap overflow vulnerability.

Educational demonstration of CVE-2024-31317 Zygote Injection Vulnerability on Android

Detailed technical analysis and working exploit for CVE-2022-0492 Linux kernel container escape via cgroup release_agent, with step-by-step lab setup…

Proof-of-concept demonstrating a use-after-free in cldflt.sys (CVE-2025-62221) that enables local privilege escalation to SYSTEM via kernel pool…

Hands-on lab demonstrating Apache Struts2 OGNL injection (CVE-2017-5638) with step-by-step system analysis, exploitation, sandbox bypass, and…

Educational simulation of CVE-2023-22809 Sudo privilege escalation vulnerability with automated Bash exploit script, lab manual, and mitigation…

Instructions for installing a vulnerable version of Exim and its expluatation

A report on Dirty Frag, which is a Linux Local Privilege Escalation (LPE) vulnerability chain that allows an unprivileged user to gain root access

Reproduce CVE-2022-32250 and CVE-2025-21756 by tampering with modprobe_path and hijacking control flow, respectively.

Practice POC scripting in Tryhackme’s intro poc scripting room (For Linux)