Purpose
Connect security practitioners, developers, and researchers with labs aligned to what matters day to day: practical vulnerabilities, modern surfaces (web, API, mobile, cloud), and DevSecOps disciplines.
Professional catalog · 65 curated labs
A reference-grade index of intentionally vulnerable applications and environments — organized for real hands-on training, tool validation, and a portfolio narrative rooted in applied security engineering.
This repository is not a casual list: it is a centralized, professional index of deliberately insecure applications, mapped to training goals — from exploitation to remediation, from code review to pipeline security.
Connect security practitioners, developers, and researchers with labs aligned to what matters day to day: practical vulnerabilities, modern surfaces (web, API, mobile, cloud), and DevSecOps disciplines.
Everything here is meant for isolated environments. The posture is explicit: controlled training, documented evidence, no inappropriate exposure — the maturity of teams that understand operational risk.
Demonstrate AppSec and DevSecOps fluency with a living artifact: curation, taxonomy, training tags (SAST, DAST, SCA, supply chain…), and a technical narrative that matches industry expectations.
Cards built for rich hover states, contextual glow, and depth — each capability maps to real lab scenarios.
Web, APIs, and classic-to-modern surfaces focused on exploration, validation, and hardening.
CI/CD, supply chain, and continuous integration as a risk vector — from commit to deploy.
Intentional scenarios to reproduce issues, test hypotheses, and build defensible evidence.
From proof-of-concept to fix: a complete narrative for teams that need to close the loop.
An ideal surface to tune SAST/DAST/SCA scanners and record findings with rigor.
Category paths and focus tags that accelerate discovery of the right lab for each objective.
Link code review, threat modeling, and security testing to the development lifecycle.
Practice security gates, policy, and tool integration without settling for toy examples.
A layered view: from the curated index to testing disciplines — clear for technical reviews and stakeholders alike.
Curation spans boundaries: beyond classic web apps, you get API, mobile, cloud, and software delivery security — the combination that defines modern product and platform teams.
Tags such as SAST, DAST, supply chain, and threat modeling help you pick the right lab in seconds.
A catalog layout designed for human reading — not merely stacking repository links.
Each entry points to the project’s official documentation — sustainable maintenance by design.
Strong fit for hiring loops, conference talks, and senior technical portfolios.
A premium read on the catalog’s axes — motion, layers, and micro-interactions.
Juice Shop, WebGoat, DVWA, and related apps — Top 10 and beyond, with controlled exploitation in mind.
Vulnerable GraphQL, REST, hybrid apps — realistic API security training.
Cloud environments, orchestration, and exposed services — cloud-native security.
Supply chain, build-time secrets, integrations — security where code becomes release.
Hubs that aggregate scenarios — faster discovery for research and teaching.
A timeline with clear visual states — from what already signals authority to what expands the frontier.
An index with categories, training tags, and upstream links — a solid base for navigation and study.
ShippedWeb, API, mobile, cloud, CI/CD, and collections — a narrative aligned with platform-era security.
ShippedNew labs and refined legends as the open-source ecosystem evolves.
In progressRole-based suggested paths — from code review to pipeline, with evidence checkpoints.
VisionA portfolio piece that signals curation, security judgment, and operational maturity — before the first exploit runs.