
DockSec
AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

OWASP Kubernetes security and compliance tool [WIP]

Automated deployment of OWASP Juice Shop on Kubernetes using kubeadm and Terraform, with integrated Trivy vulnerability scanning for DevSecOps…

Next-generation dependency vulnerability scanner with reachability analysis, SBOM generation, license audit, and container image scanning for CI/CD…

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

OWASP Honeypot, Automated Deception Framework.

Vulnerable app with examples showing how to not use secrets

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

Getting a handle on container security


Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

Nightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes…

End to End testing of Web, API, Cloud, Events and Security