labs.sarathg.me
← main site
11 LABS LOGGED — LIVE

Hands-on security labs, built to be broken.

This site contains the vulnerable applications and learning environments I have created over the years, along with those I will create in the future.

All labs are free, open source, and include their source code. Feel free to use them, modify them, and incorporate them into your own learning environments, training programs, or experiments.

VULNERABLE APPS 02
LAB-001 VULNERABLE APP

API Security Lab — ShopEasy

Two versions of the same e-commerce app — one vulnerable, one fixed. Attack BOLA, JWT flaws, broken auth, and debug leaks, then see exactly what secure code does differently.

API Security · OWASP OPEN →
LAB-002 VULNERABLE ENVIRONMENT

SOC Lab — Wazuh Log Monitoring

A complete SOC home lab guide using Wazuh on VirtualBox. Deploy the OVA, connect a Windows agent, run Kali attacks, and detect everything in the dashboard — no licence, no cloud, free forever.

Blue Team · Detection OPEN →
LAB-003 VULNERABLE ENVIRONMENT

Pandora - SAST & DAST Lab

A self-hosted security testing lab containing SonarQube, OWASP ZAP, Nessus, DVWA, and VulnShop for AppSec training and practice.

AppSec. VAPT OPEN →
INTERACTIVE LEARNING TOOLS 07
LAB-003 METHODOLOGY GUIDE

OSINT Guide — 2026 Edition

A hands-on open-source intelligence guide covering people investigation, image forensics, geolocation, dark web monitoring, and CTI workflows. Built for practitioners, updated for 2026.

OSINT · Investigation · CTI OPEN →
LAB-010 METHODOLOGY GUIDE

SOC Splunk Guide

A hands-on Splunk guide covering various SPL queries and real world application of the same.

SOC · Splunk · Monitoring OPEN →
LAB-011 METHODOLOGY GUIDE

Wazuh Windows Event ID Reference

Every Windows Security event ID mapped to the Wazuh rule that fires, its alert level and meaning. Logons, account changes, services, log clearing.

Blue Team · SIEM · Detection OPEN →
LAB-012 METHODOLOGY GUIDE

Wazuh Log Analysis Walkthrough

Query the Wazuh dashboard like an analyst: DQL syntax, the eleven searches that matter, and how to read an alert field by field.

Blue Team · SOC · Log analysis OPEN →
LAB-013 METHODOLOGY GUIDE

OSINT Tools 2026

60+ verified open-source intelligence tools sorted by the job: search, social media, domains, breach data, geolocation, threat intel and OPSEC.

OSINT · Investigation OPEN →
LAB-014 METHODOLOGY GUIDE

Pivoting, Tunneling & Port Forwarding

The pivoting techniques with a working command for each: SSH forwarding, proxychains, socat, chisel and Windows netsh. Plus HTB module prep.

Offensive · Pivoting OPEN →
LAB-004 SIMULATION

Parallax

Browser-based cybersecurity training platform with dual-role simulations — experience the same breach as both attacker and SOC defender across six real-world scenarios.

Blue Team · Red Team OPEN →
LAB-005 VISUAL EXPLAINER

Blockchain Learning Lab

Interactive visual blockchain explorer with live hash calculation and block tampering simulation. Teaches core concepts intuitively.

Cryptography · Interactive UI OPEN →
AWARENESS & SOCIAL ENGINEERING DEMOS 02
LAB-006 AWARENESS DEMO

Chameleon (Tabnabbing PoC)

Demonstrates tabnabbing attack risks. Used as a training aid in corporate security sessions to illustrate credential harvesting from hijacked tabs.

HTML/JS · Phishing PoC OPEN →
LAB-007 AWARENESS DEMO

Free Movie Ticket

Simulated phishing environment demonstrating how psychological triggers bypass technical controls during security awareness training drills.

Social Engineering OPEN →
SECURITY AUTOMATION TOOLS 01
LAB-008 AUTOMATION SCRIPT

Web Recon

Automated vulnerability analysis framework. Reduced manual recon time by ~30% through centralized asset discovery and scanning dashboards.

Shell · Python · Nmap OPEN →
OTHER PROJECTS 01
LAB-009 SIDE PROJECT

vyu

Live TV streaming for global channels with advanced content filtering and rapid auto-switching capabilities. Not security-related — included for completeness.

Streaming · Web Interface OPEN →