
DVFaaS-Damn-Vulnerable-Functions-as-a-Service
Intentionally Vulnerable Serverless Functions to understand the specifics of Serverless Security Vulnerabilities

Intentionally Vulnerable Serverless Functions to understand the specifics of Serverless Security Vulnerabilities

Controlled reproduction of CVE-2017-0144 (EternalBlue) in an isolated AWS EC2 lab — exploit analysis, Wireshark traffic capture, and MITRE ATT&CK…

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

Lord Of Active Directory - automatic vulnerable active directory on AWS

Deliberately vulnerable Terraform infrastructure for learning cloud security misconfigurations and validating IaC scanner detection across AWS and…

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

🐶 A curated list of Web Security materials and resources.

An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

Automate the creation of a lab environment complete with security tooling and logging best practices

A collection of challenge based hack-a-thons including student guide, coach guide, lecture presentations, sample/instructional code and templates. …

Metarget is a framework providing automatic constructions of vulnerable infrastructures.

BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and…

Structured collection of 500+ Hack The Box machine writeups, 400+ challenge solutions, and interactive learning tools including knowledge graphs,…

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

Writeup of CVE-2017-1002101 with sample "exploit"/escape

Hands-on lab demonstrating Kubernetes container hardening by comparing default vs. security-enhanced deployments of a vulnerable note-taking…

Simulated exploitation and mitigation of CVE-2025-54918 (Windows NTLM flaw). Includes detection scripts, Ansible patching, and CI/CD hardening.…

Lab reproduction of CVE-2026-34040: bypasses Docker/Moby AuthZ plugins using oversized (>1MB) request bodies to create privileged containers with…