
Triage-CVE-2021-26855-ProxyLogon---Microsoft-Exchange-
Hands-on CVE triage lab: analyze NVD entries, decode CVSS vectors, map CWE weaknesses, and contextualize risk for high-profile exploits like…

Hands-on CVE triage lab: analyze NVD entries, decode CVSS vectors, map CWE weaknesses, and contextualize risk for high-profile exploits like…

AI-powered CLI tool that reviews code for security vulnerabilities, bugs, and anti-patterns using LLMs. Supports local and cloud providers, git…

Lab materials and practice resources for OSCP certification preparation, including penetration testing exercises and hands-on security training…

Structured evaluation criteria framework for assessing Web Application Firewalls (WAFs), enabling users, vendors, and third parties to compare…

Browser-based Merkle tree demo — build a tree, generate inclusion proofs, recompute the root hash by hash, and replay the RFC 6962 second-preimage…

A comprehensive guide to software supply chain security. This open-source manuscript provides security professionals and developers with practical…

OWASP teaching modules covering application security fundamentals including risk management, secure software development, and operations security for…

Intentionally vulnerable web application for security training, CTF competitions, and testing security tools. Covers OWASP Top Ten vulnerabilities…

*This project is no longer maintained* OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and…

😱 A curated list of amazingly awesome OSINT

Primary Git Repository for the Zephyr Project. Zephyr is a new generation, scalable, optimized, secure RTOS for multiple hardware architectures.

A list of resources for those interested in getting started in bug bounties


A curated list of awesome OSCP resources


Source code of a multiple series of tutorials about the hypervisor. Available at: https://rayanfam.com/tutorials

Golang Secure Coding Practices guide

Offensive Software Exploitation Course