
owasp-ctf-in-a-box
Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

Vulnerable app with examples showing how to not use secrets

Source code for the Binaries of OWASP WrongSecrets

Host and manage multiple Juice Shop instances for security trainings and Capture The Flags

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

Open-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Hands-on AI security learning platform with intentionally vulnerable LLM applications. Explore OWASP Top 10 for LLMs through interactive pizza shop…

Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite.

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

A vulnerable version of Rails that follows the OWASP Top 10

Web and mobile application security training platform

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

Write-ups from completed TryHackMe rooms — Linux privilege escalation, sudo buffer overflow (CVE-2019-18634), and OWASP Top 10 (2025).