awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to owasp/securityshepherd

Open-source alternatives to SecurityShepherd

30 open-source projects similar to owasp/securityshepherd, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best SecurityShepherd alternative.

  • dineshshetty/android-insecurebankv2dineshshetty avatar

    dineshshetty/Android-InsecureBankv2

    1,444View on GitHub↗

    Vulnerable Android application for developers and security enthusiasts to learn about Android insecurities

    Java
    View on GitHub↗1,444
  • payatu/diva-androidpayatu avatar

    payatu/diva-android

    1,115View on GitHub↗

    DIVA Android - Damn Insecure and vulnerable App for Android

    Java
    View on GitHub↗1,115
  • oversecured/ovaaoversecured avatar

    oversecured/ovaa

    747View on GitHub↗

    Oversecured Vulnerable Android App

    Java
    View on GitHub↗747
  • bridgecrewio/cfngoatbridgecrewio avatar

    bridgecrewio/cfngoat

    97View on GitHub↗

    Cfngoat is Bridgecrew's "Vulnerable by Design" Cloudformation repository. Cfngoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

    View on GitHub↗97
  • bridgecrewio/terragoatbridgecrewio avatar

    bridgecrewio/terragoat

    1,289View on GitHub↗

    TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

    HCLaws-securityazure-securitycloud-security
    View on GitHub↗1,289

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • chromium/badssl.comchromium avatar

    chromium/badssl.com

    3,026View on GitHub↗

    Visit badssl.com for a list of test subdomains, including:

    HTML
    View on GitHub↗3,026
  • chuckfw/owaspbwachuckfw avatar

    chuckfw/owaspbwa

    310View on GitHub↗

    OWASP Broken Web Applications Project

    PHP
    View on GitHub↗310
  • cider-security-research/cicd-goatcider-security-research avatar

    cider-security-research/cicd-goat

    2,274View on GitHub↗

    A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

    Python
    View on GitHub↗2,274
  • cspf-founder/dodovulnerablebankC

    CSPF-Founder/DodoVulnerableBank

    0View on GitHub↗
    View on GitHub↗0
  • cyberscions/digitalbankC

    CyberScions/Digitalbank

    0View on GitHub↗
    View on GitHub↗0
  • dan7800/vulnerableandroidapporacleD

    dan7800/VulnerableAndroidAppOracle

    0View on GitHub↗
    View on GitHub↗0
  • defectdojo/django-defectdojoDefectDojo avatar

    DefectDojo/django-DefectDojo

    4,528View on GitHub↗

    DefectDojo is a vulnerability management system and application security orchestration tool. It serves as a centralized platform for importing, deduplicating, and tracking security findings from multiple scanners and tools to manage an organization's overall security posture. The system distinguishes itself by aggregating findings from various security tools into a single report and normalizing that data to prioritize remediation. It provides specific workflows for vulnerability triage and deduplication to reduce noise and redundant manual work across the software development lifecycle. The

    HTMLanalyticsappsecautomation
    View on GitHub↗4,528
  • fuzzstati0n/fuzzgoatfuzzstati0n avatar

    fuzzstati0n/fuzzgoat

    207View on GitHub↗

    A vulnerable C program for testing fuzzers.

    C
    View on GitHub↗207
  • hackademic/hackademicHackademic avatar

    Hackademic/hackademic

    325View on GitHub↗

    the main hackademic code repository

    PHP
    View on GitHub↗325
  • htbridge/pivaaH

    htbridge/pivaa

    0View on GitHub↗
    View on GitHub↗0
  • jackmannino/owasp-goatdroid-projectjackMannino avatar

    jackMannino/OWASP-GoatDroid-Project

    254View on GitHub↗

    This project is no longer maintained OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and testers on Android security. GoatDroid requires minimal dependencies and is ideal for both Android beginners as well as more advanced users. The project currently includes two applications: FourGoats, a location-based social network, and Herd Financial, a mobile banking application. There are also several feature that greatly simplify usage within a training environment or for absolute beginners who want a good introduction to working with the Androi

    Java
    View on GitHub↗254
  • jaiswalakshansh/vuldroidjaiswalakshansh avatar

    jaiswalakshansh/Vuldroid

    68View on GitHub↗

    Vuldroid is a Vulnerable Android Application made with security issues in order to demonstrate how they can occur in code

    Java
    View on GitHub↗68
  • juice-shop/juice-shopjuice-shop avatar

    juice-shop/juice-shop

    12,530View on GitHub↗

    Juice Shop is a self-contained web application designed as a platform for cybersecurity education and security training. It functions as a controlled environment containing intentional security flaws, allowing users to practice offensive security techniques and defensive coding practices while tracking their progress through a live scoreboard. The platform serves as an industry-standard benchmark for evaluating the effectiveness and detection accuracy of automated security scanning tools. By hosting a standardized set of known vulnerabilities and common attack patterns, it provides a reliable

    TypeScript24pullrequestsapplication-securityappsec
    View on GitHub↗12,530
  • lance0312/vulnappL

    Lance0312/VulnApp

    0View on GitHub↗
    View on GitHub↗0
  • logicalhacking/dvhmalogicalhacking avatar

    logicalhacking/DVHMA

    271View on GitHub↗

    Damn Vulnerable Hybrid Mobile App (DVHMA) is an hybrid mobile app (for Android) that intentionally contains vulnerabilities.

    JavaScript
    View on GitHub↗271
  • madhuakula/kubernetes-goatmadhuakula avatar

    madhuakula/kubernetes-goat

    5,686View on GitHub↗

    Kubernetes Goat is a security training environment designed for practicing the identification and exploitation of common vulnerabilities within an intentionally insecure cluster. It provides a controlled setting to simulate system exploitations, including container escapes, role misconfigurations, and server-side requests. The project utilizes scenario-based vulnerability deployment to create specific security flaws. It includes utilities for environment management that allow the cluster to be restored to a clean baseline by removing vulnerable scenarios, service accounts, and role bindings.

    HTML
    View on GitHub↗5,686
  • mwrlabs/drozermwrlabs avatar

    mwrlabs/drozer

    4,535View on GitHub↗

    Drozer is an Android security assessment framework and vulnerability scanner. It serves as a security auditor for Android devices and their installed software, providing a specialized environment for analyzing inter-process communication mechanisms and auditing application endpoints. The framework focuses on Android inter-process communication analysis, allowing for the interrogation of system services and application components. It enables the execution of specialized security modules and custom scripts to identify vulnerabilities and test the security of runtime interfaces. The system prov

    Python
    View on GitHub↗4,535
  • optiv/insecureshopoptiv avatar

    optiv/insecureshop

    257View on GitHub↗

    An Intentionally designed Vulnerable Android Application built in Kotlin.

    Kotlin
    View on GitHub↗257
  • owasp/nodegoatowasp avatar

    owasp/nodegoat

    2,051View on GitHub↗

    The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.

    HTML
    View on GitHub↗2,051
  • owasp/owasp-mstgOWASP avatar

    OWASP/owasp-mstg

    12,973View on GitHub↗

    The Mobile Application Security Testing Guide is a comprehensive manual and compliance framework for verifying the security of mobile applications. It provides a standardized reference for identifying and validating common software security weaknesses and performing reverse engineering based on industry standards. The project provides a structured set of technical processes and checklists used to audit applications against established security weakness enumerations. It encompasses guidance for analyzing application binaries and runtime behavior to identify hidden functionality and security ga

    Python
    View on GitHub↗12,973
  • owasp/wrongsecretsOWASP avatar

    OWASP/wrongsecrets

    1,448View on GitHub↗

    Welcome to the OWASP WrongSecrets game! The game is packed with real life examples of how to not store secrets in your software. Each of these examples is captured in a challenge, which you need to solve using various tools and techniques. Solving these challenges will help you recognize common…

    Java
    View on GitHub↗1,448
  • rafaeltoledo/android-securityR

    rafaeltoledo/android-security

    0View on GitHub↗
    View on GitHub↗0
  • rapid7/metasploitable3rapid7 avatar

    rapid7/metasploitable3

    5,592View on GitHub↗

    Metasploitable3 is an automated virtual machine provisioner designed to build and deploy operating system images with intentional security weaknesses. It functions as a penetration testing lab by creating vulnerable virtual machine targets used for security training, exploit development, and the validation of security tools. The system uses configuration scripts to inject vulnerabilities into Windows and Linux environments. This includes the deployment of insecure applications and services, such as web servers and databases, and the application of misconfigured system permissions to simulate

    HTML
    View on GitHub↗5,592
  • rewanth1997/damn-vulnerable-bankR

    rewanth1997/Damn-Vulnerable-Bank

    0View on GitHub↗
    View on GitHub↗0
  • securitycompass/androidlabsS

    SecurityCompass/AndroidLabs

    0View on GitHub↗
    View on GitHub↗0