
EntraGoat
A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

AI-agent skills for distributed-systems testing

CVE2PoC is a tool that helps penetration testers, bug hunters, and security researchers quickly find public exploits or PoCs related to a CVE ID

Detection scripts, patch checker & hardening guide for CVE-2026-44963 (Veeam B&R RCE)

Vulnerable ThinkPHP 8.0.4 test environment for CVE-2024-44902 nuclei template validation

🚨 Just completed an incident report on Event ID 217: Apache OFBiz Auth Bypass and Code Injection 0-Day (CVE-2023-51467). This critical vulnerability…

Proof-of-concept exploit for CVE-2026-41651, a PackageKit TOCTOU local privilege escalation, with technical analysis, detection logic, and…

Proof-of-concept exploit for CVE-2017-1000117, demonstrating command injection via git clone to write arbitrary output to a web directory.

Educational lab environment for CVE-2021-3156 (Baron Samedit) with a Dockerized vulnerable sudo target, exploit scaffold, canary test, root-cause…

SecurityTube Linux Assembly Expert x86 Exam

Reproducible lab environment for CVE-2026-46716, a critical cross-tenant RCE in Nezha Monitoring via cron API authorization bypass. Includes Nuclei…

Proof-of-concept exploit for CVE-2017-1000117 (Git clone command injection) targeting SSH, designed for vulnerability testing and educational lab…

SQL injection via unsanitized QuerySet.order_by() input

SQL injection in QuerySet.annotate(), aggregate(), and extra()

BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and…

A little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog: https://medium.com/@iknowjason/sentinel-for-purple-teaming-1…

CVE-2026-24136 | Lab khai thác lỗ hổng IDOR trên Saleor GraphQL - query order() không kiểm tra xác thực, lộ toàn bộ PII (email, địa chỉ, SĐT) của…