


Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and…

Client-side Linux virtual machine running in the browser via WebAssembly, with Tailscale networking, Dockerfile-based custom images, and CTF…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。

An authoritative list of awesome devsecops tools with the help from community experiments and contributions.

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

A GitHub Action invoking the Gemini CLI.

Enterprise-grade static code analysis platform with multi-language support, security vulnerability detection, code quality metrics, and DevOps…

An open source threat modeling tool from OWASP

Intentionally vulnerable Terraform infrastructure for learning cloud misconfiguration detection and DevSecOps practices across AWS, Azure, and GCP.


Purple Team Exercise Framework

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

The Open-Source AWS Cyber Range

Documenting your Threat Models with HCL

threatspec - continuous threat modeling, through code