


Deliberately vulnerable Flask web application with 22 security flaws across 3 difficulty levels for hands-on penetration testing and web security…

Snort 3 IDS → IPS lab on Kali. Custom detection rules + iptables enforcement against ICMP recon, Nmap SYN scans, Hydra FTP brute force, and vsftpd…

Black-box penetration test on Metasploitable 2 — Identified 3 critical vulnerabilities including CVE-2011-2523. Conducted in isolated VMware lab.…

A curated list of awesome OSCP resources

Sources of Synacktiv's challenge for leHack 2026


A Proof-of-Concept (PoC) exploit for CVE-2018-16763 (Fuel CMS - Preauthenticated Remote Code Execution).

HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux

📦 Get a clean, ready-to-go Linux box in seconds.

Everything related to Linux Forensics

Local Privilege Escalation to Root via Sudo chroot in Linux

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine…


Wazuh 4.14.4 detection rules for CVE-2026-43284 / CVE-2026-43500 (Dirty Frag) - Linux Local Privilege Escalation via page cache write