
oss-oopssec-store
Security training for the apps you actually ship. Open your browser and start hacking.

Security training for the apps you actually ship. Open your browser and start hacking.

Practical study notes and walkthroughs for PortSwigger Academy labs, covering web vulnerabilities, payloads, enumeration, and BSCP exam strategies.

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Burp Suite Certified Practitioner - Portswigger - My notes - Guide

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

CTF writeups and teaching scripts for web security, bug bounty techniques, and network forensics, with blank-value versions for active practice.

A collection of awesome penetration testing resources, tools and other shiny things

Curated library of AI agent skills for Elasticsearch, Kibana, Observability, and Security. Teaches agents correct API usage, cloud management, alert…

An interactive, self-hosted XSS training platform with 33 progressively harder challenges

Curated study guide for OSCE3 certifications (OSWE, OSEP, OSED, OSEE) covering web exploitation, post-exploitation, payload development, lab setups,…

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Intentionally vulnerable web application for security training, CTF competitions, and testing security tools. Covers OWASP Top Ten vulnerabilities…

Educational walkthrough of CVE-2018-4416, a WebKit JavaScriptCore type confusion vulnerability, with PoC, debugging setup, and analysis of common…

Curated methodology and resource collection for web application bug bounty hunting, covering reconnaissance, vulnerability analysis, and exploitation…

Educational lab environment demonstrating CVE-2019-15588 RCE command injection vulnerability for hands-on exploitation practice and learning.

Learning and hunting SQL injection bugs for 50 continuous days

Curated cybersecurity learning library with tutorials, mindmaps, vulnerable code snippets, and methodology breakdowns across web pentesting, bug…