Professional catalog · 65 curated labs

AppSec & DevSecOps Training Labs

A reference-grade index of intentionally vulnerable applications and environments — organized for real hands-on training, tool validation, and a portfolio narrative rooted in applied security engineering.

  • 65Indexed labs
  • 9Training verticals
  • OWASPThreat-aware tags
Scroll

A portfolio lab with technical depth

This repository is not a casual list: it is a centralized, professional index of deliberately insecure applications, mapped to training goals — from exploitation to remediation, from code review to pipeline security.

Purpose

Connect security practitioners, developers, and researchers with labs aligned to what matters day to day: practical vulnerabilities, modern surfaces (web, API, mobile, cloud), and DevSecOps disciplines.

Responsible execution

Everything here is meant for isolated environments. The posture is explicit: controlled training, documented evidence, no inappropriate exposure — the maturity of teams that understand operational risk.

Portfolio value

Demonstrate AppSec and DevSecOps fluency with a living artifact: curation, taxonomy, training tags (SAST, DAST, SCA, supply chain…), and a technical narrative that matches industry expectations.

What you can train with this ecosystem

Cards built for rich hover states, contextual glow, and depth — each capability maps to real lab scenarios.

AppSec labs

Web, APIs, and classic-to-modern surfaces focused on exploration, validation, and hardening.

DevSecOps labs

CI/CD, supply chain, and continuous integration as a risk vector — from commit to deploy.

Hands-on vulnerabilities

Intentional scenarios to reproduce issues, test hypotheses, and build defensible evidence.

Exploitation & remediation

From proof-of-concept to fix: a complete narrative for teams that need to close the loop.

Validation & evidence

An ideal surface to tune SAST/DAST/SCA scanners and record findings with rigor.

Guided learning

Category paths and focus tags that accelerate discovery of the right lab for each objective.

Secure SDLC

Link code review, threat modeling, and security testing to the development lifecycle.

Pipeline automation

Practice security gates, policy, and tool integration without settling for toy examples.

How the catalog is organized

A layered view: from the curated index to testing disciplines — clear for technical reviews and stakeholders alike.

Central catalog
Web · API · Mobile Cloud · K8s CI/CD · Supply chain Code review & languages
SAST DAST SCA Pentest Threat modeling Secrets & IaC

Why this is not “just another lab list”

Depth across AppSec + DevSecOps

Curation spans boundaries: beyond classic web apps, you get API, mobile, cloud, and software delivery security — the combination that defines modern product and platform teams.

  • A
    Taxonomy and training legend

    Tags such as SAST, DAST, supply chain, and threat modeling help you pick the right lab in seconds.

  • B
    Editorial structure

    A catalog layout designed for human reading — not merely stacking repository links.

  • C
    Upstream anchors

    Each entry points to the project’s official documentation — sustainable maintenance by design.

  • D
    Authority narrative

    Strong fit for hiring loops, conference talks, and senior technical portfolios.

Lab mesh modules and fronts

A premium read on the catalog’s axes — motion, layers, and micro-interactions.

Web surface

OWASP-grade applications

Juice Shop, WebGoat, DVWA, and related apps — Top 10 and beyond, with controlled exploitation in mind.

14 labsDAST · Pentest
API & Mobile

Distributed surfaces

Vulnerable GraphQL, REST, hybrid apps — realistic API security training.

10 labs
Cloud & K8s

Infrastructure as target

Cloud environments, orchestration, and exposed services — cloud-native security.

7 labs
CI/CD

Pipelines under pressure

Supply chain, build-time secrets, integrations — security where code becomes release.

7 labs
Collections

Directories & OWASP indexes

Hubs that aggregate scenarios — faster discovery for research and teaching.

20 labs

Conceptual stack and disciplines

SecEngine Core mindset
  • AppSec
  • DevSecOps
  • Secure SDLC
  • CI/CD security
  • Code review
  • Threat thinking
  • Hardening
  • Validation
  • Evidence
  • Hands-on labs

Roadmap & future direction

A timeline with clear visual states — from what already signals authority to what expands the frontier.

Structured catalog

An index with categories, training tags, and upstream links — a solid base for navigation and study.

Shipped

Multi-surface coverage

Web, API, mobile, cloud, CI/CD, and collections — a narrative aligned with platform-era security.

Shipped

Continuous expansion

New labs and refined legends as the open-source ecosystem evolves.

In progress

Guided learning paths

Role-based suggested paths — from code review to pipeline, with evidence checkpoints.

Vision

Clone, isolate, train, document

A portfolio piece that signals curation, security judgment, and operational maturity — before the first exploit runs.