

Objective: Demonstrate the exploitation of the Log4Shell vulnerability (CVE-2021-44228) within a simulated banking application environment.

Ghost CMS Content API Blind SQL Injection

Starlette Host-Header URL Confusion Lab (X41-2026-002) - CVE-2026-48710

Working POC of CVE-2026-6664 written by Sonnet 4.6

Intentionally vulnerable VM-hosted Java shop — Log4Shell (CVE-2021-44228) workshop lab (EC2 / Azure VM / GCE)

Audit de sécurité Black Box d'un serveur Drupal 7. Démonstration d'une Kill Chain complète : Injection SQL (CVE-2014-3704) ➔ RCE ➔ Reverse Shell ➔…

Exploitation for CVE-2022-26923

Automate the creation of a lab environment complete with security tooling and logging best practices

An information security preparedness tool to do adversarial simulation.

Useful resources for SOC Analyst and SOC Analyst candidates.

Here you will get awesome collection of mostly all well-known and usefull cybersecurity books from beginner level to expert for all cybersecurity…

Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from…

Blue Team detection lab created with Terraform and Ansible in Azure.

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…

System Vulnerability Checklist & Network Security Hardening project featuring reconnaissance, vsFTPd backdoor analysis (CVE-2011-2523), and active…

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…