awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectServer MCPDespreCum realizăm clasamentulPresă
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to webgoat/webgoat

Open-source alternatives to WebGoat

30 open-source projects similar to webgoat/webgoat, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best WebGoat alternative.

  • ethicalhack3r/dvwaAvatar ethicalhack3r

    ethicalhack3r/DVWA

    13,236Vezi pe GitHub↗

    DVWA is a vulnerable web application sandbox and PHP security training environment. It serves as a deployable penetration testing target and an OWASP Top 10 lab designed for practicing exploits and simulating common web security vulnerabilities. The application allows users to adjust security difficulty levels to match their skill level and toggle between different SQL database engines to test how various systems handle injection attacks. It includes a mechanism to disable authentication, enabling automated security tools to interact directly with the environment. The project provides capabi

    PHP
    Vezi pe GitHub↗13,236
  • digininja/dvwaAvatar digininja

    digininja/DVWA

    13,229Vezi pe GitHub↗

    DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities. The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks. The application is

    PHPdvwahackinginfosec
    Vezi pe GitHub↗13,229
  • rapid7/metasploitable3Avatar rapid7

    rapid7/metasploitable3

    5,592Vezi pe GitHub↗

    Metasploitable3 is an automated virtual machine provisioner designed to build and deploy operating system images with intentional security weaknesses. It functions as a penetration testing lab by creating vulnerable virtual machine targets used for security training, exploit development, and the validation of security tools. The system uses configuration scripts to inject vulnerabilities into Windows and Linux environments. This includes the deployment of insecure applications and services, such as web servers and databases, and the application of misconfigured system permissions to simulate

    HTML
    Vezi pe GitHub↗5,592

Căutare AI

Explorează mai multe repository-uri excelente

Descrie ce ai nevoie în limbaj simplu — AI-ul sortează mii de proiecte open source selectate în funcție de relevanță.

Find more with AI search
  • juice-shop/juice-shopAvatar juice-shop

    juice-shop/juice-shop

    12,530Vezi pe GitHub↗

    Juice Shop is a self-contained web application designed as a platform for cybersecurity education and security training. It functions as a controlled environment containing intentional security flaws, allowing users to practice offensive security techniques and defensive coding practices while tracking their progress through a live scoreboard. The platform serves as an industry-standard benchmark for evaluating the effectiveness and detection accuracy of automated security scanning tools. By hosting a standardized set of known vulnerabilities and common attack patterns, it provides a reliable

    TypeScript24pullrequestsapplication-securityappsec
    Vezi pe GitHub↗12,530
  • hackademic/hackademicAvatar Hackademic

    Hackademic/hackademic

    325Vezi pe GitHub↗

    the main hackademic code repository

    PHP
    Vezi pe GitHub↗325
  • audi-1/sqli-labsAvatar Audi-1

    Audi-1/sqli-labs

    5,791Vezi pe GitHub↗

    sqli-labs is a collection of intentionally vulnerable web applications and sandbox environments designed for practicing the identification and exploitation of SQL injection vulnerabilities. It serves as a cybersecurity education lab where users can experiment with database exploits in a controlled setting. The environment provides specialized modules for testing a wide range of attack vectors, including error-based, boolean-blind, and time-based injections. It specifically covers advanced techniques such as second-order injections, stacked queries, and attacks targeting HTTP headers. The pro

    PHP
    Vezi pe GitHub↗5,791
  • madhuakula/kubernetes-goatAvatar madhuakula

    madhuakula/kubernetes-goat

    5,686Vezi pe GitHub↗

    Kubernetes Goat is a security training environment designed for practicing the identification and exploitation of common vulnerabilities within an intentionally insecure cluster. It provides a controlled setting to simulate system exploitations, including container escapes, role misconfigurations, and server-side requests. The project utilizes scenario-based vulnerability deployment to create specific security flaws. It includes utilities for environment management that allow the cluster to be restored to a clean baseline by removing vulnerable scenarios, service accounts, and role bindings.

    HTML
    Vezi pe GitHub↗5,686
  • samsar4/ethical-hacking-labsAvatar Samsar4

    Samsar4/Ethical-Hacking-Labs

    3,397Vezi pe GitHub↗

    Ethical-Hacking-Labs is a comprehensive cybersecurity training curriculum and lab suite designed for learning penetration testing, network analysis, and offensive security techniques. It provides a structured environment for practicing the full attack lifecycle, from initial reconnaissance and scanning to exploitation and post-compromise analysis. The project provides instructional materials and guided exercises that cover specific technical domains, including open source intelligence research and network security courseware. It includes a practical workbook for identifying system vulnerabili

    ethical-hacking-labshackinglinux
    Vezi pe GitHub↗3,397
  • medicean/vulappsAvatar Medicean

    Medicean/VulApps

    3,781Vezi pe GitHub↗

    VulApps is a vulnerability lab orchestrator that provides managed container environments. It delivers a curated suite of containerized security tools and applications with known security flaws for use in penetration testing sandboxes and exploit research. The project focuses on the rapid deployment of isolated environments designed for practicing security attacks and verifying vulnerability patches. It includes a collection of Docker-based vulnerable application environments and pre-configured toolsets for security auditing. The system covers the orchestration of container deployments to sim

    Shellcvedockerstruts
    Vezi pe GitHub↗3,781
  • carpedm20/awesome-hackingAvatar carpedm20

    carpedm20/awesome-hacking

    15,722Vezi pe GitHub↗

    This project is a comprehensive, community-curated directory of cybersecurity resources, tools, and educational materials. It functions as a centralized index for researchers and students to discover frameworks and utilities across the entire security lifecycle, ranging from initial vulnerability assessment to post-exploitation analysis. The repository distinguishes itself through a hierarchical taxonomy that organizes diverse security disciplines into a searchable, version-controlled knowledge base. Rather than hosting software directly, it utilizes a decentralized aggregation model that lin

    awesomehacking
    Vezi pe GitHub↗15,722
  • orange-cyberdefense/goadAvatar Orange-Cyberdefense

    Orange-Cyberdefense/GOAD

    7,464Vezi pe GitHub↗

    GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of vulnerable Windows virtual machines. It serves as a security training environment for practicing Active Directory penetration testing, privilege escalation, and lateral movement across various cloud platforms and local virtualization hypervisors. The project distinguishes itself through a multi-provider infrastructure model and a system of infrastructure recipes that simulate intentional security misconfigurations. It supports the deployment of varied attack scenarios, including

    PowerShellactive-directoryansibleinfrastructure-as-code
    Vezi pe GitHub↗7,464
  • vulhub/vulhubAvatar vulhub

    vulhub/vulhub

    20,279Vezi pe GitHub↗

    Vulhub is a collection of pre-configured, containerized applications designed to serve as a standardized platform for security research, vulnerability testing, and educational exploitation exercises. It functions as an orchestration framework that enables users to deploy isolated software environments for the purpose of practicing penetration testing and analyzing common security flaws in a controlled setting. The project utilizes an infrastructure-as-code pattern to define complex, multi-service software stacks, ensuring that testing targets remain consistent and reproducible. By leveraging

    Dockerfiledockerdocker-composedockerfile
    Vezi pe GitHub↗20,279
  • trimstray/the-book-of-secret-knowledgeAvatar trimstray

    trimstray/the-book-of-secret-knowledge

    228,641Vezi pe GitHub↗

    This project serves as a centralized, community-driven repository of technical knowledge and administrative resources. It provides a structured taxonomy that aggregates disparate information into a searchable framework, supporting continuous learning and rapid problem-solving for system administrators and cybersecurity practitioners. By mapping resources across offensive security, infrastructure management, and software development, it offers a unified path for skill acquisition and professional reference. The project is defined by a command-line-first design philosophy, prioritizing terminal

    awesomeawesome-listbsd
    Vezi pe GitHub↗228,641
  • c0ny1/upload-labsAvatar c0ny1

    c0ny1/upload-labs

    4,157Vezi pe GitHub↗

    upload-labs is a file upload vulnerability lab and penetration testing sandbox. It consists of a collection of intentionally vulnerable web applications designed for practicing the discovery and exploitation of file upload security flaws. The project serves as a web security training ground and cybersecurity education lab. It provides a simulated environment for learning how to bypass upload restrictions and achieve remote code execution on servers through controlled laboratory exercises. The system includes capabilities for vulnerability research simulation and penetration testing practice.

    PHP
    Vezi pe GitHub↗4,157
  • jaykali/maskphishAvatar jaykali

    jaykali/maskphish

    3,020Vezi pe GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Shellhackhackinghacking-tool
    Vezi pe GitHub↗3,020
  • koadt/oss-oopssec-storeAvatar kOaDT

    kOaDT/oss-oopssec-store

    22Vezi pe GitHub↗

    Security training for the apps you actually ship. Open your browser and start hacking.

    TypeScript
    Vezi pe GitHub↗22
  • stamparm/dsvwAvatar stamparm

    stamparm/DSVW

    869Vezi pe GitHub↗

    Damn Small Vulnerable Web

    Python
    Vezi pe GitHub↗869
  • owasp/nodegoatAvatar owasp

    owasp/nodegoat

    2,051Vezi pe GitHub↗

    The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.

    HTML
    Vezi pe GitHub↗2,051
  • s4n7h0/xvwaAvatar s4n7h0

    s4n7h0/xvwa

    1,754Vezi pe GitHub↗

    XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.

    PHP
    Vezi pe GitHub↗1,754
  • rhinosecuritylabs/cloudgoatAvatar RhinoSecurityLabs

    RhinoSecurityLabs/cloudgoat

    3,639Vezi pe GitHub↗

    CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

    Python
    Vezi pe GitHub↗3,639
  • snoopysecurity/dvwsAvatar snoopysecurity

    snoopysecurity/dvws

    460Vezi pe GitHub↗

    Damn Vulnerable Web Services is an insecure web application with multiple vulnerable web service components that can be used to learn real world web service vulnerabilities. NOTE: This project is out of date, please use https://github.com/snoopysecurity/dvws-node

    PHP
    Vezi pe GitHub↗460
  • qazbnm456/awesome-web-securityAvatar qazbnm456

    qazbnm456/awesome-web-security

    13,097Vezi pe GitHub↗

    This project serves as a comprehensive cybersecurity training platform and resource repository focused on web application security. It functions as a centralized hub for security practitioners, providing both a curated collection of technical documentation and research, and a system for deploying isolated, containerized environments to practice security analysis and exploitation techniques. The platform distinguishes itself by integrating automated data aggregation with hands-on, container-based orchestration. It maintains a current knowledge base of industry research and digital threats whil

    awesomeawesome-listlist
    Vezi pe GitHub↗13,097
  • zhuifengshaonianhanlu/pikachuAvatar zhuifengshaonianhanlu

    zhuifengshaonianhanlu/pikachu

    4,421Vezi pe GitHub↗

    Pikachu is a web security training platform and vulnerable web application sandbox. It provides a containerized lab environment designed for practicing penetration testing and identifying common security flaws. The project serves as an OWASP Top 10 practice lab, offering a simulation suite for critical risks. It includes specific scenarios for practicing the exploitation of SQL injection, cross-site scripting, remote code execution, and broken access control. The environment covers a broad range of security testing simulations, including directory traversal, server-side request forgery, unsa

    PHPweb
    Vezi pe GitHub↗4,421
  • freedomofpress/dangerzoneAvatar freedomofpress

    freedomofpress/dangerzone

    5,536Vezi pe GitHub↗

    Dangerzone is a security tool and content sanitizer that converts untrusted files into safe PDFs. It removes malicious content by rendering documents as raw pixels within a sandboxed environment and rebuilding them as new PDF files to strip executable scripts and hidden threats. The project utilizes container-based sandboxing to isolate file processing from the host operating system. It is designed for air-gapped execution, allowing the sanitization process to operate on hardware without network connectivity to prevent malware from communicating with external servers. To maintain document ut

    Python
    Vezi pe GitHub↗5,536
  • chaitin/xrayAvatar chaitin

    chaitin/xray

    11,612Vezi pe GitHub↗

    Xray is a security assessment tool focused on web vulnerability scanning, attack surface mapping, and technology fingerprinting. It identifies common security flaws through automated scanning and semantic analysis, while verifying findings via a custom proof-of-concept execution engine. The system distinguishes itself with a containerized vulnerability testbed used to deploy pre-configured vulnerable applications. This environment allows for the simulation of specific vulnerabilities and edge-case scenarios to validate scanner accuracy and eliminate false positives. The platform covers a bro

    Vuepassive-vulnerability-scannerpocsecurity
    Vezi pe GitHub↗11,612
  • dagger/container-useAvatar dagger

    dagger/container-use

    3,556Vezi pe GitHub↗

    container-use is a containerized AI execution environment and code sandbox designed to provide a secure space for AI coding agents to execute commands and build applications. It functions as a workspace orchestrator that provisions isolated containers mapped to git branches, allowing multiple agents to operate in parallel without state conflicts or affecting the host system. The project serves as a Model Context Protocol server, bridging AI agents to containerized environments for standardized tool access. It enables a workflow for reviewing and merging changes made by agents within these iso

    Go
    Vezi pe GitHub↗3,556
  • memodb-io/acontextAvatar memodb-io

    memodb-io/Acontext

    3,035Vezi pe GitHub↗

    Acontext is an LLM orchestration backend and agent memory framework designed to manage session state and knowledge for AI agents. It functions as a context manager and orchestration layer that integrates model providers with a secure code sandbox and a zero-knowledge data store. The project is distinguished by its approach to knowledge distillation, capturing agent learnings as reusable Markdown skills and structured memory files. It provides a secure execution environment where shell commands and scripts run in isolated containers with the ability to mount these persistent skill files direct

    TypeScriptagentagent-development-kitagent-observability
    Vezi pe GitHub↗3,035
  • nvidia/openshellAvatar NVIDIA

    NVIDIA/OpenShell

    7,276Vezi pe GitHub↗

    OpenShell is a security framework and sandboxed execution runtime for autonomous AI agents. It provides isolated environments using containers and virtual machines to protect host infrastructure and sensitive data from unauthorized access during agent execution. The system distinguishes itself by combining hardware-accelerated passthrough for host GPU access with a security gateway that intercepts model API calls. This gateway manages credentials by stripping caller information and injecting backend secrets, ensuring sensitive API keys remain off the local filesystem. The platform covers bro

    Rust
    Vezi pe GitHub↗7,276
  • openinterpreter/open-interpreterAvatar openinterpreter

    openinterpreter/open-interpreter

    63,998Vezi pe GitHub↗

    Open Interpreter is an autonomous agent runtime that translates natural language instructions into executable code to interact with local software and operating systems. It functions as an orchestration framework that connects language models to a secure execution environment, enabling the development of agents capable of managing system resources and performing complex tasks. To ensure safety, the system mandates explicit user verification before executing any generated code and provides robust isolation through containerized sandboxing. The project distinguishes itself through its deep inte

    Rustchatgptgpt-4interpreter
    Vezi pe GitHub↗63,998
  • google/gvisorAvatar google

    google/gvisor

    17,748Vezi pe GitHub↗

    This project is a secure container runtime that provides strong isolation for application workloads by implementing a userspace kernel. By intercepting system calls and executing them within a memory-safe, restricted environment, it minimizes the attack surface exposed to the host kernel. It functions as a drop-in engine for standard container orchestration platforms, ensuring compatibility with industry-standard runtime specifications while maintaining a hardened execution boundary. The runtime distinguishes itself through its ability to virtualize core system resources, including an indepen

    Gocontainersdockerkernel
    Vezi pe GitHub↗17,748