
DonkAI
DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

OWASP Learning Gateway Project

Web and mobile application security training platform

a Damn Vulnerable Serverless Application

A deliberately vulnerable web application for learning web application security.

This is a defunct code base. The project is located at: https://github.com/WebGoat

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

Hands-on AI security lab platform with 50+ scenarios across prompt injection, agentic system exploitation, model manipulation, and MCP trust boundary…

Intentionally vulnerable machine learning model for hands-on security training. Explore common ML vulnerabilities, adversarial attacks, and defensive…

Open-source web application security challenge platform with auto-approved registration, SQL dump generation, and Docker deployment for hands-on…

The Governed Agentic AI Operating System — Rust + Tauri 2.0 | 65 crates, 658 commands, 84 pages, 5,029 tests, 10/10 OWASP

Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite.

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

Deliberately vulnerable Docker lab with a routable DNS estate and machine-readable answer keys per target, scoring scanner precision, recall and…

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Open-source interactive security awareness training library with 130+ SCORM exercises covering phishing, vishing, BEC, MFA fatigue, and OWASP AI/LLM…