
Azure_Workshop
Terraform-deployable vulnerable-by-design Azure lab with realistic attack paths and common misconfigurations for practicing red teaming and security…

Terraform-deployable vulnerable-by-design Azure lab with realistic attack paths and common misconfigurations for practicing red teaming and security…

Alibab-Nacos-Unauthorized-Reset PWD

Weaponizes vulnerable signed drivers to bypass EDR kernel callbacks, object callbacks, ETW TI provider, and userland hooks for LSASS memory dumping…

BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609,…

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

LdapNightmare is a PoC tool that tests a vulnerable Windows Server against CVE-2024-49113

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

Dump LSASS via physical memory read primitives in vulnerable kernel drivers

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

Powershell script for enumerating vulnerable DCOM Applications

C-based tool exploiting the vulnerable wsftprm.sys kernel driver to terminate protected EDR/AV processes on Windows, including PPL processes, via…

Python exploit for CVE-2019-19781 targeting Citrix ADC with template injection to achieve remote code execution on vulnerable gateways.

Exploit script for CVE-2025-55182 that deploys a Godzilla memory shell on vulnerable web servers, with support for proxy and encoding options.

Proof-of-concept exploit for CVE-2020-0796 (SMBGhost) remote overflow vulnerability. Python script to check and trigger the SMBv3 compression bug on…

Docker-based lab for detecting and exploiting CVE-2025-55182 (React2Shell RCE) in Next.js/React Server Components, with pre-configured vulnerable…

Python script to detect FortiOS authentication bypass (CVE-2024-55591) by probing WebSocket connections to the management interface, identifying…

A go-exploit to scan for Juniper firewalls vulnerable to CVE-2023-36845