
iam-vulnerable
Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.

Create your own vulnerable by design AWS penetration testing playground

This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo…

PowerShell-based provisioning framework for deploying complex lab environments on Hyper-V and Azure. Supports Windows, Linux, and products like AD,…

Kubernetes Security Training Platform - focusing on security mitigation

DEF CON Cloud Village workshop slides teaching KQL for cloud security log analysis, with practical exercises in a shared Azure Log Analytics…

In this workshop session, we will extract firmware from an EV charger, dig into the firmware, and eventually emulate it so we can interact with the…

Exploit CVE-2017-7494 for Net Security course final Assignment. This would reveal the vulnerability of services that run in administrative priority…

Full-cycle Pentest on Metasploitable (VMware/Kali). Scanned services (Apache Tomcat/8180), researched CVE-2002-0936 via Exploit-DB, and gained access…

Local Docker lab demonstrating CVE-2026-5718 arbitrary file upload in a WordPress plugin, with vulnerable and patched services for side-by-side…

Docker-based lab demonstrating CVE-2026-44338 authentication bypass in PraisonAI's legacy Flask API. Includes vulnerable and patched services with…

Docker-based lab demonstrating CVE-2025-58360, a critical unauthenticated XXE injection in GeoServer WMS/OWS services. Includes exploit script for…

Local Docker lab for reproducing CVE-2026-3844, an unauthenticated arbitrary file upload to RCE in the WordPress Breeze Cache plugin. Compares…

Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp…

An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

A proof of concept exploiting CVE-2022-26923.

Pen Tesing Lab exploiting VSFTPD 2.3.4 backdoor via Metasploit Framework

Exploitation for CVE-2024-49019