
CVE-2020-8559
This is a PoC exploit for CVE-2020-8559 Kubernetes Vulnerability

This is a PoC exploit for CVE-2020-8559 Kubernetes Vulnerability

Drop a single binary into a compromised Kubernetes pod and instantly map every realistic attack path to cluster-admin, node escape, secret theft,…

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

📦 Make security testing of K8s, Docker, and Containerd easier.

A collection of Windows print spooler exploits containerized with other utilities for practical exploitation.

Proof-of-concept exploit for CVE-2023-36723, an arbitrary directory creation vulnerability in Windows Container Manager, enabling privilege…

Single-script exploit for CVE-2026-44881 that chains .git credential leakage, Portainer Git-symlink injection, arbitrary host file read, and SSH…

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

Post-exploit a compromised etcd, gain persistence and remote shell to nodes.

ingress-nginx admission controller RCE escalation PoC

Docker CVE-2022-37708

Automating situational awareness for cloud penetration tests.

Curated repository of CVEs with PoCs, articles, and detailed descriptions for vulnerability research and exploitation.

Automated Zero Trust hardening and forensic auditing for VMware vCenter Server Appliance (VCSA)

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

CVE-2025-54914 exposes a critical flaw in Azure Networking that allows attackers to escalate privileges and control routing across subnets. The…

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.