
BloodBash
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Proof-of-concept exploit scripts for CVE-2024-8068 and CVE-2024-8069, focused on authorized penetration testing, educational labs, and defensive…

Educational repository for documenting and testing CVE proof-of-concept exploits inside isolated labs, virtual machines, and authorized penetration…

Multithreaded Python scanner for CVE-2026-15826 and CVE-2026-15748; checks target lists, supports verbose logging, configurable threads, and custom…

Proof-of-concept exploit resources for CVE-2026-19650 and CVE-2026-19478 targeting a GitLab GraphQL vulnerability, intended for authorized research,…

Educational CVE proof-of-concept repository with lab scripts for reproducing, testing, and analyzing specific vulnerabilities in isolated…

Reproduces CVE-2021-41773 path traversal in Apache HTTP Server 2.4.49, with PoC code, root-cause analysis, impact assessment, and mitigation guidance…

Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)

Validates and confirms the presence of CVE-2026-58231 in authorized environments via a lightweight Python script for vulnerability research,…

Ruby 4.0 Universal RCE Deserialization Gadget Chain - Draft or TODO

Educational CVE proof-of-concept repository with setup guidance for authorized vulnerability research using virtual machines, Docker, and isolated…

CVE-2026-68820 - Draft or TODO

Educational lab and proof-of-concept materials for a specific CVE, providing sandboxed scripts and templates for vulnerability research, authorized…

Educational proof-of-concept lab for CVE-2026-34348, demonstrating passkey authentication attacks in isolated environments for authorized security…

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

Automated vulnerable Active Directory lab suite for practicing penetration testing techniques, with prebuilt domains/forests and standalone attack…

CVE-2026-64638 - Draft or TODO
