
KaiMonkey
Deliberately vulnerable Terraform infrastructure for learning cloud security misconfigurations and validating IaC scanner detection across AWS and…

Deliberately vulnerable Terraform infrastructure for learning cloud security misconfigurations and validating IaC scanner detection across AWS and…

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

MDE/MDI Defender setup for Ludus

This repository holds a target infrastructure you can use for running the nimbostratus tools.

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

Proof-of-concept exploit for CVE-2026-78122, demonstrating container filesystem and environment variable exfiltration through docker-socket-proxy's…

Docker-based vulnerable lab for CVE-2026-3288 NGINX Ingress configuration injection, with exploit scripts, detection monitoring, and remediation…

Educational environment for LTAT.04.022 Homework 4.


Terraform-deployable vulnerable-by-design Azure lab with realistic attack paths and common misconfigurations for practicing red teaming and security…

a Damn Vulnerable Serverless Application

Create your own vulnerable by design AWS penetration testing playground

CNAPPgoat is an open source project designed to modularly provision vulnerable-by-design components in cloud environments.

Lord Of Active Directory - automatic vulnerable active directory on AWS

End-to-end vulnerability management lifecycle on Azure Windows Server 2025. Features OS patching and network-level compensating controls (NSG) to…

reproducing an old istio bug

Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities.

Automate the creation of a lab environment complete with security tooling and logging best practices