
multi-juicer
Host and manage multiple Juice Shop instances for security trainings and Capture The Flags

Host and manage multiple Juice Shop instances for security trainings and Capture The Flags

Source code for the Binaries of OWASP WrongSecrets

Vulnerable app with examples showing how to not use secrets

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Hands-on AI security learning platform with intentionally vulnerable LLM applications. Explore OWASP Top 10 for LLMs through interactive pizza shop…

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite.

A vulnerable version of Rails that follows the OWASP Top 10

Web and mobile application security training platform

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

Open-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

Write-ups from completed TryHackMe rooms — Linux privilege escalation, sudo buffer overflow (CVE-2019-18634), and OWASP Top 10 (2025).

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…