🔵 Blue team training environment: a complete, security-hardened Flask marketplace published with its own security audit, 278 tests, and the mistakes left visible on purpose.
-
Updated
Aug 19, 2026 - Python
🔵 Blue team training environment: a complete, security-hardened Flask marketplace published with its own security audit, 278 tests, and the mistakes left visible on purpose.
Hands-on web security lab: each vulnerability shown as an exploitable /vuln route and a fixed /secure route, with tests proving both. Covers SQLi, XSS, IDOR.
An AI security agent that really attacks: local audits + red-vs-blue drills in an isolated Docker range. 100% local, MIT. 一个会自己动手攻击的 AI 安全智能体:本机隐私/漏洞体检评分 + ReAct 智能体逐步带你处置 + 真实红蓝对抗演练场(Docker 隔离网内 Kali 攻击机 × WAF × 靶机,SQL注入真实报文)。全程本地运行,不出网,MIT 开源。
Defender-side cyber incident simulator. An abstract state machine, not real infrastructure, and reinforcement-learning policies, not LLM agents. Host status is hidden behind noisy alerts, the attacker improvises, and a web console lets you play the same scenario by hand and compare your score to a trained agent's.
Modern Cybersecurity Learning and Security Analysis Platform.
Gamified, self-hosted ICS/OT security training range.
🚩 Dynamic CTF platform with isolated container-per-user-per-challenge. Auto flag rotation, scoreboard, write-up engine.
Intentionally vulnerable store application for security training, with each flaw mapped to its CWE. Local use only - DO NOT DEPLOY.
Consent-based phishing awareness training platform — realistic simulations, zero credential storage, enforced by tests
Open-source CTF labs for LLM security -- hands-on OWASP Top 10 for LLMs with real exploits, flags, and defenses. Runs locally with Ollama.
Hard-gated social-engineering & OSINT awareness lab — campaign planning, pretext/vishing drills; consent-gated, no network-send.
Intentionally vulnerable API for security learning (5 backends: Python, Node.js, Go, PHP, Java)
Reproducible CTF/pentest range built with Vagrant + VirtualBox - 7 vulnerable machines, 90 flags, custom scoreboard. Educational, isolated.
Intentionally vulnerable Flask demo app (hardcoded creds, eval and command injection, CVE-pinned deps) with a Snyk security scan workflow
Локальная веб-лаборатория: 8 проверяемых сценариев SQLi, IDOR, XSS, SSRF, sessions, upload, CORS и debug exposure.
Ein modulares Malware-Simulationsframework für Bildungs- und Forschungszwecke. Dieses Projekt demonstriert verschiedene Techniken moderner Malware (Netzwerkverbreitung, Persistence, Evasion, C2) in einer sicheren Sandbox-Umgebung ohne tatsächliche schädliche Aktionen. Alle Funktionen werden nur simuliert und protokolliert
DVAH — Damn Vulnerable Agent Harness: a patch-the-runtime security lab for AI-agent platforms. Exploit a real architectural bug, trace it, patch the harness, and prove the security invariant holds.
Deliberately vulnerable Persian-themed e-commerce app (Flask) for hands-on web pentesting practice — 11 OWASP Top 10 / WSTG bugs, a staged student lab guide, and an instructor answer key.
Free, open-source playground for attacking real tool-calling LLM agents in your browser — indirect prompt injection, confused deputy, and MCP tool poisoning, each with a post-solve trace explaining why it worked and the control that stops it.
SPECTRE — phishing simulation framework. Clone login pages, host locally or via Cloudflare tunnel, live capture dashboard. // DEDSEC
To associate your repository with the security-training topic, visit your repo's landing page and select "manage topics."