
owasp-ctf-in-a-box
Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

Self-hosted CTF control plane for security-learning events: team registration, live leaderboard, and patch-to-score, quiz, jeopardy, and AI challenge…

UNIX-like reverse engineering framework and command-line toolset.

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

MSI Modern 15H AI C1MGT-096IT Linux thermal management - Reverse engineered EC control with fan profiles and battery threshold

https://nvd.nist.gov/vuln/detail/CVE-2022-34169

Proof-of-concept exploit for CVE-2018-14665, a local privilege escalation in Xorg on Linux distributions, with analysis and PoC for Red Hat.

Local privilege escalation exploit for CVE-2018-14665 targeting X.Org Server on OpenBSD and Linux. Provides a proof-of-concept script to gain root…

StepSecurity owned org for analyzing compromised packages

Reproducible incident micro-postmortem for on-prem Microsoft SharePoint “ToolShell” (CVE-2025-53770): ATT&CK snapshot, “logs that matter” table,…

A tool to help you manage your leaks

Simple TCP tunnel in Rust that exposes local ports to a remote server, bypassing NAT firewalls. Lightweight, self-hostable, and easy to install.

CLI tool to find email addresses of GitHub users, contributors, and organization members, with multi-threading, JSON output, and breach checking via…

Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files

A PowerShell script that automates the security assessment of Microsoft 365 environments.

A Full-Featured HexEditor compatible with Linux/Windows/MacOS

Automated GitHub dorking tool that searches user, organization, and repository code for exposed secrets, credentials, and security misconfigurations…