
Embedded-Backdoor-Connection
This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

Vulnerable app with examples showing how to not use secrets

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how…

How to Install OpenClaw on an Android Phone and Control It via WhatsApp

Hands-on challenges for learning how to reverse engineer Flutter applications.

All about CVE-2018-14667; From what it is to how to successfully exploit it.

How to set up 2 VirtualBox VM to debug kernel driver using windbg

Open-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.

This repository provides a learning environment to understand how an Exim RCE exploit for CVE-2018-6789 works.

Proof-of-concept security demo illustrating how PowerShell can create trusted-looking Windows toast notifications chained together with…

The vulnerable application that will teach you how to hack WebSockets

A cybersecurity research game measuring how humans detect AI-generated phishing emails. Built as a retro terminal experience.

A simple dockerize application that shows how to exploit the CVE-2022-42889 vulnerability.

Demo to show how Log4Shell / CVE-2021-44228 vulnerability works

Red Team AI Benchmark: Evaluating LLMs for authorized offensive-security tasks. Red Team AI Benchmark is a CLI model-evaluation benchmark. It…

This lab demonstrates the exploitation of CVE-2024-24945, a heap corruption vulnerability affecting NGINX. The objective was to understand how memory…

Goal is to triage well known attacks and learn how security teams quickly respond.

Hands-on vulnerability management case study: how Wazuh flagged a real SSRF (CVE-2025-68616) in WeasyPrint, and how I reproduced and patched it.