
purpleteam-s2-containers
Stage two containers

Stage two containers

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

Deliberately vulnerable web application portal with a containerized backend, designed for practicing exploitation of CVE-2021-44228 and container…

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Dockerized vulnerable web application demonstrating the Log4j CVE-2021-44228 remote code execution vulnerability for educational exploitation and…

Dockerized proof-of-concept exploit for CVE-2019-13956, targeting a web application vulnerability accessible via HTTP on port 8090.

The only open-source tool to analyze vulnerabilities and configuration issues with running docker container(s) and docker networks.

Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock

A collection of awesome security hardening guides, tools and other resources

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Open Source Cloud Native Application Protection Platform (CNAPP)

Integration of Clair and Docker Registry

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

Open-source, cross-platform, multi-purpose security auditing tool

Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices

Superseded by https://github.com/aquasecurity/trivy-operator

🔐 Secure, real-time monitoring dashboard for OpenClaw AI agents. Auth, TOTP MFA, cost tracking, live feed, memory browser and more.