Research & development · Theosec
Everything we break, in the open.
The workshop behind the engagements. Vulnerable machines you can own end to end, the tools we build to move faster, and writeups from real offensive-security work.
//What's here
Labs
Intentionally vulnerable machines that mirror real exam and engagement scenarios. Download the VM, read the source, and work the whole chain on your own hardware.
Tools
The utilities we build to move faster on engagements — recon, exploitation, reporting. Open where we can share them, documented, and free to use.
Writing
Technique breakdowns, findings worth generalising, and notes from the work. The thinking behind the labs and the tools, written between engagements.
Training labs
Machines built to be taken apart.
The first labs are landing soon.
A tiered set of vulnerable machines — super-easy through insane — each a single intended chain from unauthenticated access to code execution.
Tools
Built on an engagement, shared after.
Tools are on the way.
The recon, exploitation and reporting utilities we lean on — open where we can share them.
→Next step
Read the source. Break the box.
Every lab is a VM you run locally — no account, no scoreboard. Download one, trace the vulnerability through the code, and land the shell yourself.