#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

A vulnerable version of Rails that follows the OWASP Top 10
The materials of "Hypervisor 101 in Rust", a one-day long course, to quickly learn hardware-assisted virtualization technology and its application…

A fully functional DanderSpritz lab in 2 commands

Hands-on red-team obfuscation workshop teaching AMSI bypass, ETW evasion, and payload obfuscation with PowerShell, Visual Basic, and C# to evade…

Labs for Practical Malware Analysis & Triage

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and…

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).

Windows Local Privilege Escalation Cookbook

A collection of web pages vulnerable to SQL injection flaws

An example C program which contains vulnerable code for common types of vulnerabilities. It can be used to show fuzzing concepts.

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

PwnAdventure3 Server

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

intentionally vuln web Application Security in django