Ross ROSS = Recommend OSS · open-source software intelligence for agents

bkerler/exploit_me resource

Very vulnerable ARM/AARCH64 application (CTF style exploitation tutorial with 29 vulnerability techniques) observed · 2026-08-28

github.com/bkerler/exploit_me · C++ · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

80/100

  • Activity 89
  • Release rhythm 56
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3165
  • days_rel: 83
  • days_push: 66
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

1106 stars · 158 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A deliberately vulnerable ARM/ARM64 C++ application offering 29 CTF-style exploitation levels covering techniques like stack overflow, format string, ROP, and use-after-free. It is a hands-on training resource for learning binary exploitation with GDB and pwndbg.

Use cases

  • learn binary exploitation on ARM
  • practice ROP chain building
  • CTF-style exploitation training
  • study format string vulnerabilities
  • practice heap exploitation techniques
  • learn to debug ARM binaries with gdb

When to choose

  • you want hands-on practice exploiting ARM/ARM64 binaries
  • you are preparing for CTF binary exploitation challenges
  • you want guided levels covering many vulnerability classes

When to avoid

  • you need a security scanning or defensive tool
  • you only target x86 exploitation without porting
  • you want production-ready software

Facets

learning-resource · maturity active

security developer-tools security education tutorials cross-platform ctf exploitation arm aarch64 rop binary-exploitation vulnerability-training hands-on linux

1 source

Member repositories

RepositoryRoleHealth v2
bkerler/exploit_memain80

For agents

markdown · JSON · MCP: product_card(name="bkerler/exploit_me")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem