

The vulnerable application that will teach you how to hack WebSockets

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

Vulnerability triage with provenance. Resolves CVEs from locally built corpora (NVD/KEV/EPSS, ExploitDB, nmap script.db) and emits verification…

Windows protocol library, including SMB and RPC implementations, among others.

Hands-on challenges for learning how to reverse engineer Flutter applications.

Replays captured CAN bus frames to demonstrate CVE-2026-21014, showing how missing authentication and freshness checks enable unauthorized automotive…

Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…

A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench,…

Red Team AI Benchmark: Evaluating LLMs for authorized offensive-security tasks. Red Team AI Benchmark is a CLI model-evaluation benchmark. It…

Identify privilege escalation paths within and across different clouds

A curated list of Android Security materials and resources For Pentesters and Bug Hunters

This lab demonstrates the exploitation of CVE-2024-24945, a heap corruption vulnerability affecting NGINX. The objective was to understand how memory…

CVE-2026-25243 — Redis RESTORE zipmap double-free → remote code execution (ASLR on).

Research of exploit options for CVE-2024-53667 and their remediation

Exploit chain utilizing directory traversal and iOS restore to overwrite protected files.

Lightweight Python script to test username/password combinations against Zimbra webmail login pages for security assessments and password auditing.

Owa Valid Login Checker