avelino /
awesome-go
A curated list of awesome Go frameworks, libraries and software
100/100 healthLoading repository data…
joe-shenouda / repository
A curated list of hacking environments where you can train your cyber skills legally and safely
A transparent discovery signal based on current public GitHub metadata.
This score does not audit code, security, maintainers, documentation quality, or suitability. Verify the repository and its current documentation before adoption.
A curated list of hacking environments where you can train your cyber skills free, legally and safely

In the field of Information Security, understanding the enemy, the hacker, is crucial. By knowing your enemy, you can effectively defend and secure the digital world.
"Know the enemy, and you can defeat the enemy."
In the USA, even high-ranking retired police officers continue to advise residents on how to better secure their homes. They visit houses and identify weak points, sharing their knowledge of the criminals' techniques to help prevent break-ins.
To hone your cybersecurity skills, you need to keep your hacking skills up-to-date. To achieve this, a safe, legal, and free environment is necessary for practice.
This list compiles websites that offer various opportunities to practice your cyber skills. Each site has a unique approach, and a brief description is provided to highlight its focus.
Some sites offer tutorials to guide you, while others encourage self-directed exploration.
This post will be regularly updated with new sites, so bookmark it or follow me to stay informed with the latest overview.
If you are missing a site not mentioned in the list, feel free to contribute.
foleranser • filinpavel • BenDrysdale • HrushikeshK • deveyNull • nirmalunagar • roya0045 • photoelf • AverageS • pentesttools-com • Warxim
LinkedIn 🌍 Twitter 🌍 Cybersecurity News
Joe Shenouda - "Our work is no longer to secure computers alone, it's now about securing society."
Joe Shenouda is a seasoned cybersecurity expert with experience in engineering, consulting, and research. He has worked with leading companies like Verizon and Accenture, specializing in operational cybersecurity. Joe is passionate about mentoring and training the next generation of cybersecurity specialists, using industry standards like ISO, NIST, and CIS Controls to guide organizations in adopting best practices.
Accolades:
Geography: Benelux, Middle-East & Nordics (Belgium, Netherlands, Luxembourg, Denmark, Norway, Sweden, Finland, Egypt, Monaco, Vatican City)
GitHub Portfolio: https://github.com/joe-shenouda/
✨ Active security clearance ✨
Please share this list if you find it useful. Let me know if you like it
If you would like to support this project, you can make a donation through PayPal:
Don't forget to give this repo a ✨ STAR!
Ạ̸͛̀̑̚w̷̙͓͊̑̈́͂̀̈́ẻ̸̟̝̒͠s̸̛̜̣͖̘̪̦͂͂̃͛͜o̷͕̺͎͔͌̏m̵͈̝͎̓̓̀͆̂ẻ̴͕̲̳͝ ̸̺̽̋̒̚̕Ĉ̷̺̩̭̐͘͝ỳ̴̨̱͂́b̷̀̉̍̓̀͋̈́̚ͅḛ̸̲̝̈́̊̈́̾͑̏̀̒r̴̰̬̘̻͙̉̌̀͆̎ ̴̰͐S̷̫̜̖͍̋͌̎k̸̢̯͒͊̀̍̽͂͝͠ï̴̛̘͚͘l̴̤̬͕̺̙̮̱͇͊̉ḽ̷̝̣̪̘́̅s̷̼̜̀̉͒̈́
| Site name | Description |
|---|---|
| Altoro Mutual | Altoro is a fake banking website, containing various security vulnerabilities. |
| Arizona Cyber Warfare Range | The ranges offer an excellent platform for you to learn computer network attack (CNA), computer network defense (CND), and digital forensics (DF). You can play any of these roles. |
| AzureGoat | AzureGoat : A Damn Vulnerable Azure Infrastructure. |
| BodgeIt Store | The BodgeIt Store is a vulnerable web application which is currently aimed at people who are new to pen testing. |
| bWAPP | buggy web application, is a free and open source deliberately insecure web application. It helps security enthusiasts, developers and students to discover and to prevent web vulnerabilities. bWAPP prepares one to conduct successful penetration testing and ethical hacking projects. |
| Cyber Degrees | Free online cyber security Massive Open Online Courses (MOOCS). |
| Commix testbed | A collection of web pages, vulnerable to command injection flaws. |
| CryptOMG | CryptOMG is a configurable CTF style test bed that highlights common flaws in cryptographic implementations. |
| Cyber Security Base | Cyber Security Base is a page with free courses by the University of Helsinki in collaboration with F-Secure. |
| Cybersecuritychallenge UK |
Selected from shared topics, language and repository description—not editorial ratings.
avelino /
A curated list of awesome Go frameworks, libraries and software
100/100 healthDopplerHQ /
:octocat: A curated awesome list of lists of interview questions. Feel free to contribute! :mortar_board:
35/100 health| Cyber Security Challenge UK runs a series of competitions designed to test your cyber security skills. |
| CyberTraining 365 | Cybertraining365 has paid material but also offers free classes. The link is directed at the free classes. |
| Cybrary.it | Free and Open Source Cyber Security Learning. |
| Damn Small Vulnerable Web | Damn Small Vulnerable Web (DSVW) is a deliberately vulnerable web application written in under 100 lines of code, created for educational purposes. It supports the majority of (most popular) web application vulnerabilities together with appropriate attacks. |
| Damn Vulnerable Android App | Damn Vulnerable Android App (DVAA) is an Android application which contains intentional vulnerabilities. |
| Damn Vulnerable Hybrid Mobile App | Damn Vulnerable Hybrid Mobile App (DVHMA) is a hybrid mobile app (for Android) that intentionally contains vulnerabilities. |
| Damn Vulnerable iOS App | Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. |
| Damn Vulnerable Linux | Damn Vulnerable Linux (DVL) is everything a good Linux distribution isn't. Its developers have spent hours stuffing it with broken, ill-configured, outdated, and exploitable software that makes it vulnerable to attacks. |
| Damn Vulnerable Router Firmware | The goal of this project is to simulate a real-world environment to help people learn about other CPU architectures outside of the x86_64 space. This project will also help people get into discovering new things about hardware. |
| Damn Vulnerable Stateful Web App | Short and simple vulnerable PHP web application that naïve scanners found to be perfectly safe. |
| Damn Vulnerable Thick Client App | DVTA is a Vulnerable Thick Client Application developed in C# .NET with many vulnerabilities. |
| Damn Vulnerable Web App | Damn Vulnerable Web Application (DVWA) is a PHP/MySQL web application that is damn vulnerable. Its main goal is to be an aid for security professionals to test their skills and tools in a legal environment, help web developers better understand the processes of securing web applications and to aid both students & teachers to learn about web application security in a controlled class room environment. |
| Damn Vulnerable Web Services | Damn Vulnerable Web Services is an insecure web application with multiple vulnerable web service components that can be used to learn real-world web service vulnerabilities. |
| Damn Vulnerable Web Sockets | Damn Vulnerable Web Sockets (DVWS) is a vulnerable web application which works on web sockets for client-server communication. |
| Damnvulnerable.me | A deliberately vulnerable modern-day app with lots of DOM-related bugs. |
| Dareyourmind | Online game, hacker challenge (mirror archive). |
| Defbox | Experience real-Life Cyber Threats in a safe Environment. |
| DIVA Android | Damn Insecure and vulnerable App for Android. |
| ENISA Training Material | The European Union Agency for Network and Information Security (ENISA) Cyber Security Training. You will find training materials, handbooks for teachers, toolsets for students and Virtual Images to support hands-on training sessions. |
| exploit.co.il Vulnerable Web App | exploit.co.il Vulnerable Web app designed as a learning platform to test various SQL injection Techniques. |
| Exploit-exercises.com | exploit-exercises.com provides a variety of virtual machines, documentation and challenges that can be used to learn about a variety of computer security issues such as privilege escalation, vulnerability analysis, exploit development, debugging, reverse engineering, and general cyber security issues. |
| ExploitMe Mobile | Set of labs and an exploitable framework for you to hack mobile an application on Android. |
| GameOver | Project GameOver was started with the objective of training and educating newbies about the basics of web security and educate them about the common web attacks and help them understand how they work. |
| Gh0stlab | A security research network where like-minded individuals could work together towards the common goal of knowledge. |
| GOAD (Game Of Active Directory) | GOAD is a pentest active directory LAB project. The purpose of this lab is to give pentesters a vulnerable Active directory environment ready to use to practice usual attack techniques. |
| GoatseLinux | GSL is a Vmware image you can run for penetration testing purposes. |
| Google Gruyere | Labs that cover how an application can be attacked using common web security vulnerabilities, like cross-site scripting vulnerabilities (XSS) and cross-site request forgery (XSRF). Also, you can find labs how to find, fix, and avoid these common vulnerabilities and other bugs that have a security impact, such as denial-of-service, information disclosure, or remote code execution. |
| Gracefully Vulnerable Virtual Machine | Graceful’s VulnVM is VM web app designed to simulate a simple eCommerce style website which is purposely vulnerable to a number of well know security issues commonly seen in web appl |
josephmisiti /
A curated list of awesome Machine Learning frameworks, libraries and software.
83/100 healthvuejs /
🎉 A curated list of awesome things related to Vue.js
93/100 healthfffaraz /
A curated list of awesome C++ (or C) frameworks, libraries, resources, and shiny things. Inspired by awesome-... stuff.
99/100 healthComposioHQ /
A curated list of awesome Claude Skills, resources, and tools for customizing Claude AI workflows
84/100 health