This site contains the vulnerable applications and learning environments I have created over the years, along with those I will create in the future.
All labs are free, open source, and include their source code. Feel free to use them, modify them, and incorporate them into your own learning environments, training programs, or experiments.
Two versions of the same e-commerce app — one vulnerable, one fixed. Attack BOLA, JWT flaws, broken auth, and debug leaks, then see exactly what secure code does differently.
A complete SOC home lab guide using Wazuh on VirtualBox. Deploy the OVA, connect a Windows agent, run Kali attacks, and detect everything in the dashboard — no licence, no cloud, free forever.
A self-hosted security testing lab containing SonarQube, OWASP ZAP, Nessus, DVWA, and VulnShop for AppSec training and practice.
A hands-on open-source intelligence guide covering people investigation, image forensics, geolocation, dark web monitoring, and CTI workflows. Built for practitioners, updated for 2026.
A hands-on Splunk guide covering various SPL queries and real world application of the same.
Every Windows Security event ID mapped to the Wazuh rule that fires, its alert level and meaning. Logons, account changes, services, log clearing.
Query the Wazuh dashboard like an analyst: DQL syntax, the eleven searches that matter, and how to read an alert field by field.
60+ verified open-source intelligence tools sorted by the job: search, social media, domains, breach data, geolocation, threat intel and OPSEC.
The pivoting techniques with a working command for each: SSH forwarding, proxychains, socat, chisel and Windows netsh. Plus HTB module prep.
Browser-based cybersecurity training platform with dual-role simulations — experience the same breach as both attacker and SOC defender across six real-world scenarios.
Interactive visual blockchain explorer with live hash calculation and block tampering simulation. Teaches core concepts intuitively.
Demonstrates tabnabbing attack risks. Used as a training aid in corporate security sessions to illustrate credential harvesting from hijacked tabs.
Simulated phishing environment demonstrating how psychological triggers bypass technical controls during security awareness training drills.