Build AI-powered security tools. 50+ hands-on labs covering ML, LLMs, RAG, threat detection, DFIR, and red teaming. Includes Colab notebooks, Docker environment, and CTF challenges.
-
Updated
Sep 25, 2026 - Python
Build AI-powered security tools. 50+ hands-on labs covering ML, LLMs, RAG, threat detection, DFIR, and red teaming. Includes Colab notebooks, Docker environment, and CTF challenges.
Hands-on secure code review training: learn to find vulnerabilities in Flask, Django, FastAPI through production-quality examples. Whitebox pentesting for modern web frameworks.
A repository of Security Engineering exercises: these exercises are designed to prepare you for interviews.
Open-source prompt injection attack console. Test AI security by firing categorized attacks at any endpoint.
Intentionally vulnerable AI security training lab for LLM agents — demonstrates OWASP LLM Top 10 2025: RAG injection, tool abuse, memory poisoning, supply chain compromise, data exfiltration and more.
Este proyecto es un simulador de ciberseguridad diseñado para entornos educativos. Permite a estudiantes practicar técnicas de ataque y defensa en un entorno controlado, replicando situaciones reales de ciberseguridad sin riesgo para sistemas en producción.
Open-source cybersecurity training instruments designed for hands-on technical analysis, vulnerability identification, and skill verification.
Mainframers is RPG is an educational text-based role-playing game (RPG) with a sneakers theme that aims to teach players about IBM mainframe penetration testing and cybersecurity.
This repository is designed for educational purposes, with real code, real labs, and real-world logic — but zero bullshit.
Intentionally vulnerable Python / Flask application, built for educational purposes.
This live course, “AI Attack Surface: The 10 Most Critical Threats to ML and AI Systems”, offers practical, step-by-step guidance to identify, analyze, and mitigate AI-specific attack vectors.
Intentionally vulnerable captive portal lab for wireless security training. Demonstrates session hijacking, authentication bypass, and network security vulnerabilities. Docker containerized for safe, isolated learning environments. FOR EDUCATIONAL USE ONLY.
Hard-gated social-engineering & OSINT awareness lab — campaign planning, pretext/vishing drills; consent-gated, no network-send.
A collection of containerized security vulnerabilities including privilege escalation CVEs and SUID exploits for hands-on penetration testing practice.
Provides containerized ethical hacking labs using Docker and Docker Compose for hands-on cybersecurity training, penetration testing, and vulnerability assessment practice.
An AI security agent that really attacks: local audits + red-vs-blue drills in an isolated Docker range. 100% local, MIT. 一个会自己动手攻击的 AI 安全智能体:本机隐私/漏洞体检评分 + ReAct 智能体逐步带你处置 + 真实红蓝对抗演练场(Docker 隔离网内 Kali 攻击机 × WAF × 靶机,SQL注入真实报文)。全程本地运行,不出网,MIT 开源。
Intentionally vulnerable Flask demo app (hardcoded creds, eval and command injection, CVE-pinned deps) with a Snyk security scan workflow
Ein modulares Malware-Simulationsframework für Bildungs- und Forschungszwecke. Dieses Projekt demonstriert verschiedene Techniken moderner Malware (Netzwerkverbreitung, Persistence, Evasion, C2) in einer sicheren Sandbox-Umgebung ohne tatsächliche schädliche Aktionen. Alle Funktionen werden nur simuliert und protokolliert
WattzGOAT is an intentionally vulnerable web application.
To associate your repository with the security-training topic, visit your repo's landing page and select "manage topics."