
HybridTestFramework
End to End testing of Web, API, Cloud, Events and Security

End to End testing of Web, API, Cloud, Events and Security

OWASP Honeypot, Automated Deception Framework.

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.


Vulnerable app with examples showing how to not use secrets

Nightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

Stage two containers

Vulnerability Assessment Scanner with Report Generation

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…