Hands-on cybersecurity projects built for learning, experimentation, and practical security research — featuring offensive and defensive tools, automation scripts, and real-world simulations for ethical hacking practice.
| Project | Description |
|---|---|
| Subdomain Enumeration Tool | Brute-force and DNS-based subdomain discovery |
| Directory Brute-Force Tool | Automated wordlist-based directory discovery |
| Network Vulnerability Scanner | Scans for open ports and exposed services |
| Sniff Network Traffic Tool | Captures and analyzes network packets |
| Web App Crawler + Vuln Correlator | Crawls applications and correlates attack paths |
| Automated Vulnerability Scanner Integration | Orchestrates multiple scanning tools |
| Project | Description |
|---|---|
| XSS Finder | Detects reflected and stored cross-site scripting |
| SQLi Tester | Detects and safely tests injection vectors |
| CSRF Checker | Identifies cross-site request forgery points |
| CSRF Exploit Demo Kit | Chained CSRF attack demonstrations for training |
| Web Sockets Pentest Tool | Tests real-time communication channels for flaws |
| API Abuse & Fuzzing Tool | Tests REST/GraphQL endpoints for abuse cases |
| Mobile App Vulnerability Scanner | Static and dynamic mobile app testing |
| Project | Description |
|---|---|
| Wi-Fi Security Tester | Evaluates home Wi-Fi network weaknesses |
| DNS Spoofing Simulator | Practices detection and attack methods |
| ARP Spoof / MITM Tool (Lab) | Explores man-in-the-middle traffic interception |
| Packet Injection Tool | Crafts and sends custom network packets |
| TLS Downgrade & MITM Tester | Examines TLS configuration weaknesses |
| Wireless Protocol Fuzzing | Tests Zigbee, LoRa, and 802.11 frame handling |
| Network Pivoting Lab Scripts | Simulates lateral movement across networks |
| Project | Description |
|---|---|
| Reverse Shell Framework | Generates and manages shells in a lab environment |
| Exploit Template Library | Reusable exploit skeletons |
| Shell Upload Tool | Uploads payloads to target test hosts |
| Create Custom Payloads | Modular payload generator |
| ROP Chain Builder Helper | Builds return-oriented programming payloads |
| Binary Instrumentation Toolkit | Hooks and manipulates running processes |
| Vulnerability PoC Repository | Catalog of proof-of-concept exploits |
| Exploit Chaining Workflow | Automates multi-step exploit sequences |
| Password Cracking with GPUs | GPU-accelerated password cracking |
| Password Spraying Automation | Tests credential reuse patterns |
| Credential Dump Analyzer | Parses and analyzes leaked credential sets |
| Simple Password Cracker | Dictionary/brute-force cracker for learning |
| Password Manager Attack Simulations | Tests vault export and weaknesses |
| Side-Channel Attack Experiments | Timing and power analysis study |
| Project | Description |
|---|---|
| Basic Keylogger (Lab-Only) | Learn keystroke capture mechanics |
| Simple Ransomware Simulator | Sandbox-based behavior analysis |
| Malware Obfuscation Practice | Tests packing and obfuscation techniques |
| Rootkit Practice (Sandbox) | Create and remove benign rootkits |
| Kernel Backdoor Detector/Creator (Lab) | Studies kernel-level persistence techniques |
| Steganography Encoder/Decoder | Hides data within images and audio |
| Binary Reverse-Engineering Exercises | Unpacks and analyzes binaries |
| Firmware Reverse-Engineering | Finds flaws in embedded firmware |
| Log Evasion Simulator | Studies evasion techniques in a safe environment |
| IDS/IPS Bypass Tests | Crafts payloads to evade detection systems |
| Obfuscation & Packer Research Toolkit | Studies the effects of packers |
| C2 Mini Framework | Lab-based command & control functionality |
| Project | Description |
|---|---|
| IoT Device Fuzzing Tool | Fuzzes protocols used by IoT devices |
| Bluetooth Protocol Tester | Scans and tests Bluetooth services |
| USB Implant Simulator | Emulates malicious USB behaviors in a lab |
| Hardware Fault Injection Lab | Observes failure-mode vulnerabilities |
| Project | Description |
|---|---|
| Phishing Campaign Simulator | Creates safe phishing training simulations |
| Automate Phishing Page Builder | Fast, lab-only phishing page templates |
| Social Engineering Toolkit | Email/SMS template simulator for training |
| Dark Web Scraper (Research) | Aggregates threat intelligence data |
| Browser Extension for Security Testing | Injects and scans pages for testing |
| Project | Description |
|---|---|
| Smart Contract Audit Tools (Offensive POV) | Detects vulnerabilities in smart contracts |
| Blockchain Pentest Harness | Tests contract functions and flows |
| Cloud Misconfiguration Exploit Scripts | Targets insecure cloud configurations |
| Basic Honeypot | Set up to catch and log attackers |
| Red / Blue Exercise Scenarios Generator | Creates realistic red/blue team engagements |
| Project | Description |
|---|---|
| Snort/Suricata IDS Setup | Basic intrusion detection deployment |
| Host-Based Monitoring Scripts | File integrity and process watchers |
| SIEM Dashboard for Logs | Ingests and visualizes security events |
| Threat Detection Using ML | Anomaly detection prototype |
| Log Aggregation & Parser Tools | Normalizes and searches log data |
| Vulnerability Management Dashboard | Tracks the lifecycle of security findings |
| Rootkit Detection & Removal Toolkit | Heuristic-based rootkit scanning |
| Project | Description |
|---|---|
| Digital Forensic Analysis Lab | Captures and analyzes forensic artifacts |
| Basic Malware Analysis Sandbox | Safely runs and observes malware samples |
| Forensic Timeline Builder | Correlates artifacts into event timelines |
| Malware Behavior Analyzer | Extracts behavioral indicators of compromise |
| Project | Description |
|---|---|
| TLS Setup & Hardening Guide | Secure communication configuration guide |
| Two-Factor Authentication Demo | Demonstrates 2FA flows and bypass testing |
| Configure Firewall Rule Automation | Templates and testing scripts for firewall rules |
| Full-Disk Encryption Demo & Key Management | Best practices for disk encryption |
| Secure Web Application Template | Hardened starter application |
| Secure API Authentication Examples | JWT/OAuth best-practice implementations |
| Microservices Security Checklist & Tests | Secures inter-service communications |
| Project | Description |
|---|---|
| Cloud Security Posture Tool | Detects misconfigurations and risky permissions |
| Container Security Hardening Scripts | Scans and enforces container image standards |
| Secure CI/CD Pipeline Examples | Signing, scanning, and gating practices |
| SCADA/ICS Security Study Lab | Emulates industrial protocols safely |
| Data Leak Prevention Demo | Detects data exfiltration patterns |
| Project | Description |
|---|---|
| Honeynet | Distributed honeypots with centralized logging |
| Threat Intel Collection & Enrichment Pipeline | Enriches indicators of compromise (IOCs) |
| Ransomware Detection Playbook | Detects and prevents encryption activity |
All offensive projects are intended for authorized, lab, or educational use only.
