Category: Arsenal Lab

vulnerable Android Application

DVAC: An intentionally vulnerable Android Application

The Damne Vulnerable Android Components – DVAC Damn Vulnerable Android Components (DVAC) is an educational Android application intentionally designed to expose and demonstrate vulnerabilities related to various Android components such as Activities, Intents, Content...

Damn Vulnerable GCP Infrastructure

GCPGoat: A Damn Vulnerable GCP Infrastructure

GCPGoat: A Damn Vulnerable GCP Infrastructure Compromising an organization’s cloud infrastructure is like sitting on a gold mine for attackers. And sometimes, a simple misconfiguration or a vulnerability in web applications, is all an...

Damn Vulnerable SCA Application

SCAGoat : Damn Vulnerable SCA Application

SCAGoat SCAGoat is an application for Software Composition Analysis (SCA) that focuses on vulnerable and compromised JAR dependencies used in development code, providing users with hands-on learning opportunities to understand potential attack scenarios. It...

Kubernetes Goat

kubernetes goat: “Vulnerable by Design” Kubernetes Cluster

Kubernetes Goat The Kubernetes Goat designed to be an intentionally vulnerable cluster environment to learn and practice Kubernetes security. 🏁 Scenarios Sensitive keys in codebases DIND (docker-in-docker) exploitation SSRF in the Kubernetes (K8S) world Container...

CTFd

CTFd: Capture The Flag framework

What is CTFd? CTFd is a Capture The Flag framework focusing on ease of use and customizability. It comes with everything you need to run a CTF and it’s easy to customize with plugins...

CI/CD Goat

CI/CD Goat: deliberately vulnerable CI/CD environment

cicd-goat The CI/CD Goat project allows engineers and security practitioners to learn and practice CI/CD security through a set of 10 challenges, enacted against a real, full-blown CI/CD environment. The scenarios are of varying...