awesome-repositories.com
Blog
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to koadt/oss-oopssec-store

Open-source alternatives to Oss Oopssec Store

30 open-source projects similar to koadt/oss-oopssec-store, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Oss Oopssec Store alternative.

  • rhinosecuritylabs/cloudgoatRhinoSecurityLabs avatar

    RhinoSecurityLabs/cloudgoat

    3,639View on GitHub↗

    CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

    Python
    View on GitHub↗3,639
  • audi-1/sqli-labsAudi-1 avatar

    Audi-1/sqli-labs

    5,791View on GitHub↗

    sqli-labs is a collection of intentionally vulnerable web applications and sandbox environments designed for practicing the identification and exploitation of SQL injection vulnerabilities. It serves as a cybersecurity education lab where users can experiment with database exploits in a controlled setting. The environment provides specialized modules for testing a wide range of attack vectors, including error-based, boolean-blind, and time-based injections. It specifically covers advanced techniques such as second-order injections, stacked queries, and attacks targeting HTTP headers. The pro

    PHP
    View on GitHub↗5,791
  • hackademic/hackademicHackademic avatar

    Hackademic/hackademic

    325View on GitHub↗

    the main hackademic code repository

    PHP
    View on GitHub↗325
  • snoopysecurity/dvwssnoopysecurity avatar

    snoopysecurity/dvws

    460View on GitHub↗

    Damn Vulnerable Web Services is an insecure web application with multiple vulnerable web service components that can be used to learn real world web service vulnerabilities. NOTE: This project is out of date, please use https://github.com/snoopysecurity/dvws-node

    PHP
    View on GitHub↗460
  • jerryhoff/webgoat.netjerryhoff avatar

    jerryhoff/WebGoat.NET

    252View on GitHub↗

    OWASP WebGoat.NET

    C#
    View on GitHub↗252

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • juice-shop/juice-shopjuice-shop avatar

    juice-shop/juice-shop

    12,530View on GitHub↗

    Juice Shop is a self-contained web application designed as a platform for cybersecurity education and security training. It functions as a controlled environment containing intentional security flaws, allowing users to practice offensive security techniques and defensive coding practices while tracking their progress through a live scoreboard. The platform serves as an industry-standard benchmark for evaluating the effectiveness and detection accuracy of automated security scanning tools. By hosting a standardized set of known vulnerabilities and common attack patterns, it provides a reliable

    TypeScript24pullrequestsapplication-securityappsec
    View on GitHub↗12,530
  • m6a-uds/dvcam6a-UdS avatar

    m6a-UdS/dvca

    211View on GitHub↗

    Damn Vulnerable Cloud Application

    CSS
    View on GitHub↗211
  • rapid7/hackazonrapid7 avatar

    rapid7/hackazon

    1,035View on GitHub↗

    A modern vulnerable web app

    HTML
    View on GitHub↗1,035
  • tegal1337/0l4bstegal1337 avatar

    tegal1337/0l4bs

    341View on GitHub↗

    Cross-site scripting labs for web application security enthusiasts

    PHP
    View on GitHub↗341
  • adamdoupe/wackopickoadamdoupe avatar

    adamdoupe/WackoPicko

    350View on GitHub↗

    WackoPicko is a vulnerable web application used to test web application vulnerability scanners.

    PHP
    View on GitHub↗350
  • momenbasel/htb-writeupsmomenbasel avatar

    momenbasel/htb-writeups

    123View on GitHub↗

    The most comprehensive Hack The Box writeup collection - 500+ machines, 400+ challenges, interactive knowledge graph, skill trees, attack path diagrams, ProLabs, Sherlocks, OSCP/CPTS/CRTO prep. Browse: momenbasel.github.io/htb-writeups

    HTML
    View on GitHub↗123
  • webgoat/webgoatWebGoat avatar

    WebGoat/WebGoat

    9,160View on GitHub↗

    WebGoat is a deliberately insecure web application designed as an interactive security lab for learning how to identify and exploit common web vulnerabilities. It serves as a containerized sandbox that allows for the simulation and experimentation of web-based attacks and penetration testing techniques without risking production systems. The project functions as a learning lab that maps specific insecure coding patterns to structured lessons. It implements simulated server-side flaws to provide a hands-on environment for studying common security vulnerabilities and defensive coding practices.

    JavaScript
    View on GitHub↗9,160
  • s4n7h0/xvwas4n7h0 avatar

    s4n7h0/xvwa

    1,754View on GitHub↗

    XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.

    PHP
    View on GitHub↗1,754
  • madhuakula/kubernetes-goatmadhuakula avatar

    madhuakula/kubernetes-goat

    5,686View on GitHub↗

    Kubernetes Goat is a security training environment designed for practicing the identification and exploitation of common vulnerabilities within an intentionally insecure cluster. It provides a controlled setting to simulate system exploitations, including container escapes, role misconfigurations, and server-side requests. The project utilizes scenario-based vulnerability deployment to create specific security flaws. It includes utilities for environment management that allow the cluster to be restored to a clean baseline by removing vulnerable scenarios, service accounts, and role bindings.

    HTML
    View on GitHub↗5,686
  • antonio-morales/fuzzing101antonio-morales avatar

    antonio-morales/Fuzzing101

    3,796View on GitHub↗

    Fuzzing101 is an educational resource providing a structured curriculum and containerized security labs for learning software fuzzing and vulnerability research. It functions as a training course that guides users through the process of identifying security flaws using systematic input manipulation and memory corruption analysis. The project distinguishes itself by providing isolated environments that ensure consistent build dependencies for practicing software instrumentation and crash triaging. It includes a practical tutorial on using evolutionary fuzzing engines and instrumentation tools

    View on GitHub↗3,796
  • facebook/fbctffacebook avatar

    facebook/fbctf

    6,553View on GitHub↗

    fbctf is a Capture The Flag platform designed for hosting cybersecurity competitions. It provides a scoring engine to track participant progress and an orchestration tool to manage the transition from event configuration to an active state. The system utilizes a containerized deployment framework to launch the infrastructure and environments required for live events. It includes an identity integration that authenticates participants via external directory servers to provide organization-wide access control. The platform covers the administration of competition content and security goals, te

    Hack
    View on GitHub↗6,553
  • grepstrength/swiss-cheese-softwareG

    grepStrength/swiss-cheese-software

    0View on GitHub↗
    View on GitHub↗0
  • himadriganguly/sqlilabshimadriganguly avatar

    himadriganguly/sqlilabs

    101View on GitHub↗

    Lab set-up for learning SQL Injection Techniques

    JavaScript
    View on GitHub↗101
  • ine-labs/awsgoatine-labs avatar

    ine-labs/AWSGoat

    2,025View on GitHub↗

    AWSGoat : A Damn Vulnerable AWS Infrastructure

    PHP
    View on GitHub↗2,025
  • mpirnat/lets-be-bad-guysmpirnat avatar

    mpirnat/lets-be-bad-guys

    190View on GitHub↗

    The Internet is a dangerous place, filled with evildoers out to attack your code for fun or profit, so it's not enough to just ship your awesome new web app--you have to take the security of your application, your users, and your data seriously. You'll get into the mindset of the bad guys as we…

    HTML
    View on GitHub↗190
  • nccgroup/sadcloudnccgroup avatar

    nccgroup/sadcloud

    778View on GitHub↗

    A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure

    HCL
    View on GitHub↗778
  • nvisium/django.nvnVisium avatar

    nVisium/django.nV

    208View on GitHub↗

    django.nV

    JavaScript
    View on GitHub↗208
  • owasp/serverless-goatOWASP avatar

    OWASP/Serverless-Goat

    329View on GitHub↗

    OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

    Python
    View on GitHub↗329
  • paralax/lfi-labsparalax avatar

    paralax/lfi-labs

    335View on GitHub↗

    small set of PHP scripts to practice exploiting LFI, RFI and CMD injection vulns

    PHP
    View on GitHub↗335
  • qmemcpy/bettermotherfuckingctfQ

    qmemcpy/bettermotherfuckingctf

    0View on GitHub↗

    A single image is worth more than a thousand ~~bytes~~ words:

    View on GitHub↗0
  • sagishahar/lpeworkshopsagishahar avatar

    sagishahar/lpeworkshop

    2,091View on GitHub↗

    Windows / Linux Local Privilege Escalation Workshop

    Batchfile
    View on GitHub↗2,091
  • samsar4/ethical-hacking-labsSamsar4 avatar

    Samsar4/Ethical-Hacking-Labs

    3,397View on GitHub↗

    Ethical-Hacking-Labs is a comprehensive cybersecurity training curriculum and lab suite designed for learning penetration testing, network analysis, and offensive security techniques. It provides a structured environment for practicing the full attack lifecycle, from initial reconnaissance and scanning to exploitation and post-compromise analysis. The project provides instructional materials and guided exercises that cover specific technical domains, including open source intelligence research and network security courseware. It includes a practical workbook for identifying system vulnerabili

    ethical-hacking-labshackinglinux
    View on GitHub↗3,397
  • secureskytechnology/badlibrarySecureSkyTechnology avatar

    SecureSkyTechnology/BadLibrary

    59View on GitHub↗

    vulnerable web application for training

    JavaScript
    View on GitHub↗59
  • sonofagl1tch/awsdetonationlabsonofagl1tch avatar

    sonofagl1tch/AWSDetonationLab

    73View on GitHub↗

    This script is used to generate some basic detections of the aws security services

    Shell
    View on GitHub↗73
  • sonuoffsec/dvapS

    sonuoffsec/DVAP

    0View on GitHub↗
    View on GitHub↗0