
offensive-one-liners
110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

Automates CVE-2026-42945 exploitation in NGINX containers: verifies vulnerable targets, brute-forces heap offsets, executes commands, and opens an…


Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Hands-on homelab simulating the Log4Shell (CVE-2021-44228) vulnerability. Deploy Docker containers to build a vulnerable target and attacker machine,…

Customizable Linux Persistence Tool for Security Research and Detection Engineering.


cve-unassigned-1

Pentester-focused Docker registry tool to enumerate and pull images

insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.

Post-exploit a compromised etcd, gain persistence and remote shell to nodes.

A collection of manifests that will create pods with elevated privileges.

Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

Nuclio Dashboard (NOP mode) accepts unauthenticated POST /api/functions. The spec.handler field isn't path-validated, so…