A laboratory for learning secure web and mobile development in a practical manner.
☆971Sep 25, 2024Updated last year
Alternatives and similar repositories for secDevLabs
Users that are interested in secDevLabs are comparing it to the libraries listed below
Sorting:
- Repo for all the SKF Docker lab examples☆462Aug 2, 2024Updated last year
- This Lab contain the sample codes which are vulnerable to Server-Side Request Forgery attack☆762Aug 21, 2023Updated 2 years ago
- vulnerable single sign on☆150Aug 1, 2024Updated last year
- Fuzzing Payloads to Assist in Web Application Testing.☆166Jun 6, 2019Updated 6 years ago
- Linux post exploitation framework written in bash designed to assist red teams in persistence, reconnaissance, privilege escalation and l…☆542Apr 14, 2021Updated 4 years ago
- List of Awesome Asset Discovery Resources☆2,370Jan 22, 2025Updated last year
- This repository will serve as the "master" repo containing all trainings and tutorials done in preperation for OSWE in conjunction with t…☆931Jan 6, 2025Updated last year
- SSRF (Server Side Request Forgery) testing resources☆2,483Oct 12, 2024Updated last year
- Linux Local Privesc Helper and Agent☆166Dec 2, 2019Updated 6 years ago
- Penetration tests guide based on OWASP including test cases, resources and examples.☆2,764Mar 23, 2022Updated 3 years ago
- ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.☆2,438Jun 11, 2025Updated 8 months ago
- A python script that filters, checks the validity, generates clickable link(s) of subdomain(s), and reports their status☆89Oct 29, 2020Updated 5 years ago
- a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations…☆536Mar 27, 2022Updated 3 years ago
- Extract (links/possible endpoints) from responses & filter them via decoding/sorting☆93Aug 27, 2019Updated 6 years ago
- A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, al…☆2,184Dec 11, 2022Updated 3 years ago
- A curated list of amazingly awesome Burp Extensions☆3,372Feb 17, 2026Updated last week
- Course content, lab setup instructions and documentation of our very popular Breaking and Pwning Apps and Servers on AWS and Azure hands …☆950Nov 26, 2022Updated 3 years ago
- This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory☆883Dec 15, 2025Updated 2 months ago
- Local file inclusion exploitation tool☆929Oct 1, 2025Updated 5 months ago
- Pop shells like a master.☆1,489Apr 2, 2019Updated 6 years ago
- Red Team Scripts by d0nkeys (ex SnadoTeam)☆703Jul 27, 2020Updated 5 years ago
- Windows / Linux Local Privilege Escalation Workshop☆1,003Jan 15, 2019Updated 7 years ago
- Sample vulnerable code and its exploit code☆190Mar 14, 2021Updated 4 years ago
- InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable…☆1,737Feb 16, 2026Updated 2 weeks ago
- A Microservices-based framework for the study of Network Security and Penetration Test techniques☆629Jun 17, 2025Updated 8 months ago
- Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥☆7,375Aug 28, 2025Updated 6 months ago
- Scan for misconfigured S3 buckets across S3-compatible APIs!☆2,997Dec 11, 2025Updated 2 months ago
- Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.☆6,082Aug 14, 2024Updated last year
- Automated Red Team Infrastructure deployement using Docker☆1,261Aug 24, 2022Updated 3 years ago
- This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage clou…☆2,803Sep 17, 2024Updated last year
- Attack and defend active directory using modern post exploitation adversary tradecraft activity☆4,799Jul 29, 2025Updated 7 months ago
- The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application pen…☆5,150Feb 8, 2024Updated 2 years ago
- An intentionally designed broken web application based on REST API.☆578Jun 10, 2021Updated 4 years ago
- Exploitation for XSS☆731Aug 5, 2021Updated 4 years ago
- The Swiss Army knife for automated Web Application Testing☆2,322May 8, 2024Updated last year
- Active Directory Assessment and Privilege Escalation Script☆1,132Dec 7, 2022Updated 3 years ago
- Red Team Tool Kit☆1,133Dec 8, 2022Updated 3 years ago
- My Recon Automation☆194May 28, 2021Updated 4 years ago
- Create a vulnerable active directory that's allowing you to test most of the active directory attacks in a local lab☆2,257Apr 12, 2024Updated last year