Our OSCP repo: from popping shells to mental health.
-
Updated
May 31, 2022 - JavaScript
Our OSCP repo: from popping shells to mental health.
Interactive offensive security cheat sheet — 5000+ pentest commands across 50+ categories with instant search, full CRUD, write-ups, favorites and variable fill-bar. OSCP/OSWE/OSEP/CPTS/CKS/CKA/DCA exam prep ready. Docker deployable.
Modular single-file web shell framework with pure-PHP recon, SOCKS5 pivoting, and per-build fingerprinting
A unified, interactive reference for Living Off The Land Binaries (LOLBAS & GTFOBins). Features a dynamic payload builder (LHOST/LPORT), real-time search, MITRE ATT&CK mapping, and auto-updates from official sources.
BuggyBuy: Deliberately Vulnerable MERN Stack Web Application for Security Testing
CVE-2026-46490 — samlify <2.13.0 SAML AttributeValue XML injection -> signed-assertion privilege escalation. Self-contained PoC, verified e2e.
Firebase Pentesting Toolkit: Extract session tokens, dump misconfigured Firestore collections, and exploit Missing Authorization (BOLA) flaws. Includes a full 6-vulnerability case study.
Interactive attack-path explorer. Click to expand each step from a foothold to Domain Admin or root, with commands, tools, OPSEC notes, and cited primary sources.
Visualize Oracle DB user permissions with a network graph in the browser
Add a description, image, and links to the privilege-escalation topic page so that developers can more easily learn about it.
To associate your repository with the privilege-escalation topic, visit your repo's landing page and select "manage topics."