
OWASP-Learning-Gateway
OWASP Learning Gateway Project

OWASP Learning Gateway Project

Open-source web application security challenge platform with auto-approved registration, SQL dump generation, and Docker deployment for hands-on…

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

This is a defunct code base. The project is located at: https://github.com/WebGoat

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

Open-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

Host and manage multiple Juice Shop instances for security trainings and Capture The Flags

Open-source interactive security awareness training library with 130+ SCORM exercises covering phishing, vishing, BEC, MFA fatigue, and OWASP AI/LLM…

Hands-on AI security lab platform with 50+ scenarios across prompt injection, agentic system exploitation, model manipulation, and MCP trust boundary…

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.

Lab report analyzing CVE-2025-68613 expression injection in n8n, demonstrating sandbox escape via crafted payloads to access sensitive server files,…

Twitter vulnerable snippets

AzureGoat : A Damn Vulnerable Azure Infrastructure

GCPGoat : A Damn Vulnerable GCP Infrastructure

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

Some good resources for getting started with application security