awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to fofapro/vulfocus

Projects sharing features with Vulfocus

24 open-source projects similar to fofapro/vulfocus, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • orange-cyberdefense/goadOrange-Cyberdefense avatar

    Orange-Cyberdefense/GOAD

    7,464View on GitHub↗

    GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of vulnerable Windows virtual machines. It serves as a security training environment for practicing Active Directory penetration testing, privilege escalation, and lateral movement across various cloud platforms and local virtualization hypervisors. The project distinguishes itself through a multi-provider infrastructure model and a system of infrastructure recipes that simulate intentional security misconfigurations. It supports the deployment of varied attack scenarios, including

    PowerShellactive-directoryansibleinfrastructure-as-code
    View on GitHub↗7,464
  • iknowjason/awesome-cloudsec-labsiknowjason avatar

    iknowjason/Awesome-CloudSec-Labs

    2,109View on GitHub↗

    Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

    View on GitHub↗2,109
  • c0ny1/upload-labsc0ny1 avatar

    c0ny1/upload-labs

    4,157View on GitHub↗

    upload-labs is a file upload vulnerability lab and penetration testing sandbox. It consists of a collection of intentionally vulnerable web applications designed for practicing the discovery and exploitation of file upload security flaws. The project serves as a web security training ground and cybersecurity education lab. It provides a simulated environment for learning how to bypass upload restrictions and achieve remote code execution on servers through controlled laboratory exercises. The system includes capabilities for vulnerability research simulation and penetration testing practice.

    PHP
    View on GitHub↗4,157
  • hxsecurity/terraformgoatH

    HXSecurity/TerraformGoat

    0View on GitHub↗
    View on GitHub↗0

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • metarget/metargetM

    Metarget/metarget

    0View on GitHub↗
    View on GitHub↗0
  • audi-1/sqli-labsAudi-1 avatar

    Audi-1/sqli-labs

    5,791View on GitHub↗

    sqli-labs is a collection of intentionally vulnerable web applications and sandbox environments designed for practicing the identification and exploitation of SQL injection vulnerabilities. It serves as a cybersecurity education lab where users can experiment with database exploits in a controlled setting. The environment provides specialized modules for testing a wide range of attack vectors, including error-based, boolean-blind, and time-based injections. It specifically covers advanced techniques such as second-order injections, stacked queries, and attacks targeting HTTP headers. The pro

    PHP
    View on GitHub↗5,791
  • digininja/dvwadigininja avatar

    digininja/DVWA

    13,229View on GitHub↗

    DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities. The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks. The application is

    PHPdvwahackinginfosec
    View on GitHub↗13,229
  • do0dl3/xss-labsD

    do0dl3/xss-labs

    0View on GitHub↗
    View on GitHub↗0
  • firmianay/iot-vulhubF

    firmianay/IoT-vulhub

    0View on GitHub↗
    View on GitHub↗0
  • ine-labs/awsgoatine-labs avatar

    ine-labs/AWSGoat

    2,025View on GitHub↗

    AWSGoat : A Damn Vulnerable AWS Infrastructure

    PHP
    View on GitHub↗2,025
  • j3ers3/hello-java-secj3ers3 avatar

    j3ers3/Hello-Java-Sec

    1,758View on GitHub↗

    ☕️ Java Security,安全编码和代码审计

    Javacode-auditjava-secjava-vul
    View on GitHub↗1,758
  • landgrey/springbootvulexploitLandGrey avatar

    LandGrey/SpringBootVulExploit

    6,136View on GitHub↗

    SpringBootVulExploit is a collection of scanning and auditing tools designed to identify vulnerabilities, information leaks, and execution vectors within Java-based application frameworks, specifically targeting Spring Boot applications. It provides a suite of exploit techniques, payloads, and security checklists for performing vulnerability analysis. The project features capabilities for triggering remote code execution through injection vectors, deserialization payloads, and malicious configuration files. It includes a scanner for detecting exposed environment variables and internal routing

    Javarcespring-actuator-vulnerabilityspring-boot-vulnerability
    View on GitHub↗6,136
  • lemono0/fastjsonpartylemono0 avatar

    lemono0/FastJsonParty

    1,220View on GitHub↗

    FastJson全版本Docker漏洞环境(涵盖1.2.47/1.2.68/1.2.80等版本),主要包括JNDI注入及高版本绕过、waf绕过、文件读写、原生反序列化、利用链探测绕过、不出网利用等。从黑盒的角度覆盖FastJson深入利用

    Python
    View on GitHub↗1,220
  • madhuakula/kubernetes-goatmadhuakula avatar

    madhuakula/kubernetes-goat

    5,686View on GitHub↗

    Kubernetes Goat is a security training environment designed for practicing the identification and exploitation of common vulnerabilities within an intentionally insecure cluster. It provides a controlled setting to simulate system exploitations, including container escapes, role misconfigurations, and server-side requests. The project utilizes scenario-based vulnerability deployment to create specific security flaws. It includes utilities for environment management that allow the cluster to be restored to a clean baseline by removing vulnerable scenarios, service accounts, and role bindings.

    HTML
    View on GitHub↗5,686
  • rhinosecuritylabs/cloudgoatRhinoSecurityLabs avatar

    RhinoSecurityLabs/cloudgoat

    3,639View on GitHub↗

    CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

    Python
    View on GitHub↗3,639
  • swagxz/encrypt-labsS

    SwagXz/encrypt-labs

    0View on GitHub↗
    View on GitHub↗0
  • tangxiaofeng7/secexampleT

    tangxiaofeng7/SecExample

    0View on GitHub↗
    View on GitHub↗0
  • vulhub/vulhubvulhub avatar

    vulhub/vulhub

    20,279View on GitHub↗

    Vulhub is a collection of pre-configured, containerized applications designed to serve as a standardized platform for security research, vulnerability testing, and educational exploitation exercises. It functions as an orchestration framework that enables users to deploy isolated software environments for the purpose of practicing penetration testing and analyzing common security flaws in a controlled setting. The project utilizes an infrastructure-as-code pattern to define complex, multi-service software stacks, ensuring that testing targets remain consistent and reproducible. By leveraging

    Dockerfiledockerdocker-composedockerfile
    View on GitHub↗20,279
  • webgoat/webgoatWebGoat avatar

    WebGoat/WebGoat

    9,160View on GitHub↗

    WebGoat is a deliberately insecure web application designed as an interactive security lab for learning how to identify and exploit common web vulnerabilities. It serves as a containerized sandbox that allows for the simulation and experimentation of web-based attacks and penetration testing techniques without risking production systems. The project functions as a learning lab that maps specific insecure coding patterns to structured lessons. It implements simulated server-side flaws to provide a hands-on environment for studying common security vulnerabilities and defensive coding practices.

    JavaScript
    View on GitHub↗9,160
  • bishopfox/badpodsB

    BishopFox/badPods

    0View on GitHub↗
    View on GitHub↗0
  • c0ny1/vulstudyc0ny1 avatar

    c0ny1/vulstudy

    2,443View on GitHub↗

    使用docker快速搭建各大漏洞靶场,目前可以一键搭建17个靶场。

    Shelldocker-image-buildervulnerability
    View on GitHub↗2,443
  • c0ny1/xxe-labC

    c0ny1/xxe-lab

    0View on GitHub↗
    View on GitHub↗0
  • cider-security-research/cicd-goatcider-security-research avatar

    cider-security-research/cicd-goat

    2,274View on GitHub↗

    A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

    Python
    View on GitHub↗2,274
  • davidprowe/badblooddavidprowe avatar

    davidprowe/BadBlood

    2,251View on GitHub↗

    BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is a domain similar to a domain in the real world. After BadBlood is ran on a domain, security analysts and engineers can practice using tools to gain an understanding and prescribe to securing Active Directory. Each time this tool runs, it produces different results. The domain, users, groups, computers and permissions are different. Every. Single. Time.

    PowerShell
    View on GitHub↗2,251