
kubescape
Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

Open-source Kubernetes security platform scanning clusters, manifests, and images for misconfigurations, vulnerabilities, and compliance against NSA,…

Penetration tests guide based on OWASP including test cases, resources and examples.

Terraform-based Azure security lab with intentionally misconfigured environments for hands-on attack and compromise practice. Includes scenario flows…

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.…

Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container image signature…

CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific…

Local Linux enumeration script that identifies privilege escalation vectors including misconfigurations, world-writable files, clear-text passwords,…

OpenClarity is an open source platform built to enhance security and observability of cloud native applications and infrastructure

An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents

Kubernetes Security Training Platform - focusing on security mitigation

A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.

Open-source cloud security platform that discovers attack paths, identifies misconfigurations, visualizes IAM access, and provides step-by-step…

BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and…

Open Cloud Security Posture Management Engine

OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

Apache Solr RCE via Velocity template

Detailed writeup and step-by-step proof-of-concept for CVE-2020-11107, a Windows XAMPP privilege escalation vulnerability allowing arbitrary command…