
oscp-notes-2026
OSCP field notebook by Samson Laird: merged technique vault, numbered notes (MIT)

OSCP field notebook by Samson Laird: merged technique vault, numbered notes (MIT)

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

Proof-of-concept exploit targeting GeoVision GV-ASWeb Notification Settings to achieve authenticated remote code execution via command injection and…

Curated study guide for OSCE3 certifications (OSWE, OSEP, OSED, OSEE) covering web exploitation, post-exploitation, payload development, lab setups,…

XSS-based C2 that turns a victim's browser into a proxy for internal scanning, URL fetch, cookie theft, JS execution, and data exfiltration via…

HTB OneTwoSeven full walkthrough: deterministic creds, chroot symlink escape, rewrite-rule bypass RCE, CVE-2024-1086 to root

Step-by-step penetration testing walkthrough for a HackTheBox Linux box: API enumeration, vertical privilege escalation, OS command injection,…

Curated repository of CVEs with PoCs, articles, and detailed descriptions for vulnerability research and exploitation.

There are many cheat sheets out there, but this is mine.

Technical analysis and proof-of-concept for CVE-2026-34197, a critical authenticated RCE in Apache ActiveMQ via Jolokia MBeans leading to remote…

Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on

Exploit framework for CVE-2026-6875, a pre-auth RCE in ServiceNow. Chains JS injection, sandbox escape, and root privesc. Includes interactive shell,…

Proof-of-concept exploit for CVE-2022-30190 (Follina) enabling remote code execution via malicious Office documents using the ms-msdt URI scheme…

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE

Objective: Demonstrate the exploitation of the Log4Shell vulnerability (CVE-2021-44228) within a simulated banking application environment.

Docker-based multi-stage attack emulation lab demonstrating CVE-2017-5638 and CVE-2021-41773 exploitation, lateral movement, and Suricata IDS…

Python exploit for CVE-2025-8110, a Gogs symlink traversal vulnerability enabling authenticated arbitrary file write to RCE via SSH keys, crontab,…

Proof-of-concept for CVE-2025-33053 WebDAV RCE with .url file hijacking, decoy execution, and simulated C2. Includes Docker-based setup, payload…