
tandasat.github.io
Remote hypervisor development class for security researchers; covers virtualization internals, hypervisor security, and vulnerabilities in privileged…

Remote hypervisor development class for security researchers; covers virtualization internals, hypervisor security, and vulnerabilities in privileged…

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

Educational walkthrough of CVE-2018-4416, a WebKit JavaScriptCore type confusion vulnerability, with PoC, debugging setup, and analysis of common…

CTF writeups and teaching scripts for web security, bug bounty techniques, and network forensics, with blank-value versions for active practice.

Curated collection of Python scripts and tutorials for penetration testing, web security, and exploitation techniques, designed for security…

Intentionally vulnerable web application for security training, CTF competitions, and testing security tools. Covers OWASP Top Ten vulnerabilities…

Evidence-focused malware reverse engineering with deep PE/.NET inspection, Ghidra reconstruction, AI cross-checks, YARA, and ELF debugging

Practical study notes and walkthroughs for PortSwigger Academy labs, covering web vulnerabilities, payloads, enumeration, and BSCP exam strategies.


OSWE, OSEP, OSED, OSEE

Source code of a multiple series of tutorials about the hypervisor. Available at: https://rayanfam.com/tutorials

Offensive Software Exploitation Course

A curated list of awesome OSCP resources


Course materials for hackaday.io Ghidra training

A collection of useful links for Pentesters

Red Team Guides

Zyrox: LLVM based, compile-time obfuscator plugin.