awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
vulhub avatar

vulhub/vulhub

0
View on GitHub↗
20,279 stars·4,761 forks·Dockerfile·mit·21 viewsvulhub.org↗

Vulhub

Vulhub is a collection of pre-configured, containerized applications designed to serve as a standardized platform for security research, vulnerability testing, and educational exploitation exercises. It functions as an orchestration framework that enables users to deploy isolated software environments for the purpose of practicing penetration testing and analyzing common security flaws in a controlled setting.

The project utilizes an infrastructure-as-code pattern to define complex, multi-service software stacks, ensuring that testing targets remain consistent and reproducible. By leveraging declarative service orchestration, it automates the startup sequence and network connectivity of interconnected containers, allowing researchers to simulate realistic, vulnerable application architectures. The environment lifecycle is ephemeral, providing automated tools to create, manage, and destroy instances to maintain a clean state across research sessions.

Beyond its core deployment capabilities, the platform supports a range of workflows including security tooling validation, vulnerability analysis, and hands-on security training. Users can monitor container health, inspect application logs, and modify internal configurations to perform deep analysis of specific software components. The repository is structured to facilitate the rapid setup of standardized targets for testing and educational purposes.

Features

  • Vulnerable Lab Environments - Offers a collection of pre-configured containerized applications for security research and educational exploitation exercises.
  • Vulnerable Targets - Orchestrates pre-configured, intentionally vulnerable software instances for security research and educational testing.
  • Security Research Platforms - Provides a standardized framework for deploying isolated software targets to practice penetration testing and analyze security flaws.
  • Research Environments - Deploys isolated and standardized containerized targets to safely practice exploitation techniques and analyze vulnerabilities.
  • Container Orchestration & Deployment - Automates the provisioning and lifecycle management of isolated software environments using container orchestration.
  • DevSecOps and Automation - Pre-built vulnerable environments for testing.
  • Remote Exploitation - Collection of vulnerable environments for testing.
  • Vulnerability Scanners - Collection of vulnerable environments.
  • Vulnerability Labs - Docker-based collection of pre-configured vulnerable environments.
  • Security Tools - Listed in the “Security Tools” section of the Awesome Hacking awesome list.
  • Vulnerability Environments - Pre-configured environments for testing and reproducing known security vulnerabilities.
  • Vulnerable Applications - Pre-built vulnerable environments based on docker-compose.
  • Infrastructure as Code - Defines complex multi-service software stacks as version-controlled configuration files for consistent testing.
  • Sandboxing Environments - Provides an orchestration tool for managing ephemeral, isolated environments to safely test malicious payloads.
  • Service Orchestration Configurations - Coordinates multi-container service dependencies and networking through declarative configuration files.
  • Ephemeral Environments - Provisions short-lived, reproducible execution contexts for security research and testing.
  • Security Tools - Facilitates testing of security monitoring tools by deploying known vulnerable services for simulated attacks.
  • Environment Lifecycle Management - Provides tools for starting, stopping, and removing isolated software instances to maintain clean testing environments.
  • Vulnerability Research and Analysis - Supports vulnerability analysis by setting up specific software versions to reproduce flaws and verify mitigations.

Star history

Star history chart for vulhub/vulhubStar history chart for vulhub/vulhub

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Vulhub

Similar open-source projects, ranked by how many features they share with Vulhub.
  • rapid7/metasploitable3rapid7 avatar

    rapid7/metasploitable3

    5,592View on GitHub↗

    Metasploitable3 is an automated virtual machine provisioner designed to build and deploy operating system images with intentional security weaknesses. It functions as a penetration testing lab by creating vulnerable virtual machine targets used for security training, exploit development, and the validation of security tools. The system uses configuration scripts to inject vulnerabilities into Windows and Linux environments. This includes the deployment of insecure applications and services, such as web servers and databases, and the application of misconfigured system permissions to simulate

    HTML
    View on GitHub↗5,592
  • apsdehal/awesome-ctfapsdehal avatar

    apsdehal/awesome-ctf

    11,614View on GitHub↗

    This project is a comprehensive directory of software utilities, frameworks, and educational resources designed for cybersecurity competitions and offensive security research. It serves as a centralized index for tools used in cryptography, forensics, reverse engineering, and web exploitation, while providing structured materials for training and skill development. The repository distinguishes itself through a community-driven maintenance model that aggregates and organizes technical resources into a searchable, hierarchical structure. It facilitates knowledge transfer by cataloging expert pr

    JavaScriptawesomectfpenetration
    View on GitHub↗11,614
  • orange-cyberdefense/goadOrange-Cyberdefense avatar

    Orange-Cyberdefense/GOAD

    7,464View on GitHub↗

    GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of vulnerable Windows virtual machines. It serves as a security training environment for practicing Active Directory penetration testing, privilege escalation, and lateral movement across various cloud platforms and local virtualization hypervisors. The project distinguishes itself through a multi-provider infrastructure model and a system of infrastructure recipes that simulate intentional security misconfigurations. It supports the deployment of varied attack scenarios, including

    PowerShellactive-directoryansibleinfrastructure-as-code
    View on GitHub↗7,464
  • webgoat/webgoatWebGoat avatar

    WebGoat/WebGoat

    9,160View on GitHub↗

    WebGoat is a deliberately insecure web application designed as an interactive security lab for learning how to identify and exploit common web vulnerabilities. It serves as a containerized sandbox that allows for the simulation and experimentation of web-based attacks and penetration testing techniques without risking production systems. The project functions as a learning lab that maps specific insecure coding patterns to structured lessons. It implements simulated server-side flaws to provide a hands-on environment for studying common security vulnerabilities and defensive coding practices.

    JavaScript
    View on GitHub↗9,160
See all 30 alternatives to Vulhub→

Frequently asked questions

What does vulhub/vulhub do?

Vulhub is a collection of pre-configured, containerized applications designed to serve as a standardized platform for security research, vulnerability testing, and educational exploitation exercises. It functions as an orchestration framework that enables users to deploy isolated software environments for the purpose of practicing penetration testing and analyzing common security flaws in a controlled setting.

What are the main features of vulhub/vulhub?

The main features of vulhub/vulhub are: Vulnerable Lab Environments, Vulnerable Targets, Security Research Platforms, Research Environments, Container Orchestration & Deployment, DevSecOps and Automation, Remote Exploitation, Vulnerability Scanners.

What are some open-source alternatives to vulhub/vulhub?

Open-source alternatives to vulhub/vulhub include: rapid7/metasploitable3 — Metasploitable3 is an automated virtual machine provisioner designed to build and deploy operating system images with… apsdehal/awesome-ctf — This project is a comprehensive directory of software utilities, frameworks, and educational resources designed for… orange-cyberdefense/goad — GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of… webgoat/webgoat — WebGoat is a deliberately insecure web application designed as an interactive security lab for learning how to… qazbnm456/awesome-web-security — This project serves as a comprehensive cybersecurity training platform and resource repository focused on web… joaomatosf/jexboss — jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit…