
Open-source interactive security awareness training library with 130+ SCORM exercises covering phishing, vishing, BEC, MFA fatigue, and OWASP AI/LLM scenarios for LMS deployment.
130+ free, open-source security awareness training exercises for employees — hands-on, interactive SCORM modules covering phishing awareness training, phishing simulation, GDPR training, EU AI Act compliance, AI security (OWASP Top 10 for LLM and Agentic Applications), and more. Free for individuals, nonprofits, and small businesses with fewer than 25 employees. Discounted Enterprise pricing for universities and educational institutions. Built for people who want to retain what they learn and share it with others.

👥 Talk to the Founders | 🔗 Browse the Full Library | 🎮 Try a live phishing awareness demo
Most security awareness training is forgettable: boring slide decks, soulless videos, and lately, AI-generated materials that turn people off. The problem isn't the content itself, it's the format. Because passive learning doesn't build habits. People sit through a 10-minute video, click "Complete," and forget everything.
This free, open-source security awareness training library takes a different approach: interactive, gamified, first-person exercises.
Every exercise drops you into an interactive 3D office environment where you face realistic incidents in first-person. You interact with real objects: a phone, a PC running a live OS (browser, terminal, Zoom), a flipchart. And make decisions under pressure, just like you would at your desk.
Scenarios include things like:
The goal is to build muscle memory so that when something bad is about to happen at work, people remember having faced it before — and respond accordingly. Every exercise ends with a quiz at a 100% pass threshold to confirm the knowledge is stuck.
Every exercise is a SCORM .zip file — ready to import into any LMS (Moodle, TalentLMS, Docebo, Cornerstone, SAP SuccessFactors, Workday Learning, and any other SCORM 1.2 / 2004 compliant platform), embed into your existing training pipeline, or test on SCORM Cloud before rollout. That makes this one of the easiest free security awareness training options to deploy across a small team.
The repo root contains full course packages. The Individual Exercises folder contains standalone exercises if you want to build a custom security awareness curriculum.
The content is fully white-labeled — no logos, no backlinks, no attribution required inside the modules. Who can use it, and on what terms, is covered in the license section below.
This open-source security awareness training library is published under the RansomLeak Community License (see LICENSE). It is free to use if you are:
Under the free license you can import the modules into any LMS, run them for your team, embed them in your own employee security awareness training program, and use them in workshops you deliver. Redistributing or reselling the content as a standalone product is prohibited, and so is delivering it to third-party clients as a service (see security awareness training for MSPs).
No training budget? If you're above 25 employees but don't have budget for security awareness training, contact us. We regularly agree individual terms in exchange for co-marketing (a case study, a testimonial, a logo on our site, or a review).
A university, school, or other educational institution? Institutional use (training staff, faculty, or students at scale) is covered by the Enterprise Plan at an education discount. Contact us with your institution's details for pricing.
25 or more employees, or need a DPA, a vendor contract, always-current content, or custom scenarios? The Enterprise Plan is for you. It includes a full commercial license for your headcount plus everything your security and procurement teams will ask for. Drop us a line for pricing.
Earlier releases of this repository were published under CC BY-NC 4.0. Copies obtained under that license remain subject to its terms; everything published from this version onward is under the RansomLeak Community License.