
GOAD
Automated vulnerable Active Directory lab suite for practicing penetration testing techniques, with prebuilt domains/forests and standalone attack…

Automated vulnerable Active Directory lab suite for practicing penetration testing techniques, with prebuilt domains/forests and standalone attack…

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how…

Web and mobile application security training platform

Damn Vulnerable MCP Server

An information security preparedness tool to do adversarial simulation.

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

AzureGoat : A Damn Vulnerable Azure Infrastructure

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

Deliberately vulnerable web application lab for practicing exploitation of SQLi, XSS, CSRF, SSTI, IDOR, XXE, and 15+ other common web security flaws…

The Open-Source AWS Cyber Range

GCPGoat : A Damn Vulnerable GCP Infrastructure

:wrench: Deploy customizable Active Directory labs in Azure - automatically.

NOTICE This repository contains the public FTC SDK for the SKYSTONE (2019-2020) competition season. If you are looking for the current season's FTC…

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.