Stars
OSWE-style white-box web exploitation lab. A Flask monitoring app with chained RCE paths buried in normal business logic — practice source-code review.
Six-layer call-stack spoofing via .pdata lacunae — defeats ETW-Ti, kernel callbacks, CET shadow stack, and return-address validation in a single composite chain.
Reverse engineering focusing on x64 Windows.
EvilVM compiler for information security research tools.
Leaked Mirai Source Code for Research/IoC Development Purposes
📡 PoC auto collect from GitHub.
A Curated list of Security Resources for all connected things
GreenPlasma CTF Analysis — the missing SYSTEM shell piece
Vulnerable server used for learning software exploitation
This repository will serve as the "master" repo containing all exploit code and notes in regards to the Modern Binary Exploitation course by RPISEC.
HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux
A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.
Cybersecurity AI (CAI), the framework for AI Security
Free educational content on reverse engineering and malware analysis from the FLARE team
Community curated list of templates for the nuclei engine to find security vulnerabilities.
Extract Windows credentials directly from VM memory snapshots and virtual disks
SigPloit: Telecom Signaling Exploitation Framework - SS7, GTP, Diameter & SIP
[漏洞复现] 全球首款单文件利用 CVE-2023-4357 Chrome XXE 漏洞 EXP, 实现对访客者本地文件窃取. Chrome XXE vulnerability EXP, allowing attackers to obtain local files of visitors.
A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.