#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

Vulnerable app with examples showing how to not use secrets
A collection of challenge based hack-a-thons including student guide, coach guide, lecture presentations, sample/instructional code and templates. …

Offensive Software Exploitation Course

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how…

A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific…

This is a resource factory for anyone looking forward to starting bug hunting and would require guidance as a beginner.

A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development

AI Red Teaming playground labs to run AI Red Teaming trainings including infrastructure.

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is…

PowerShell-based provisioning framework for deploying complex lab environments on Hyper-V and Azure. Supports Windows, Linux, and products like AD,…

Materials for Windows Malware Analysis training (volume 1)

HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

A toolset to make a system look as if it was the victim of an APT attack

⚔️Windows11 Penetration Suite Toolkit 🔰 The First Windows Penetration Testing Environment on Mac M Chips

Intentionally vulnerable Terraform infrastructure for learning cloud misconfiguration detection and DevSecOps practices across AWS, Azure, and GCP.