Try searching for "database", "file", "API", or browse by category
45 Tools in Vulnerable Labs
IWA-Java
by fortify
Insecure Web + API application with example Fortify integrations into many DevSecOps and CICD platforms
IWA-DotNet
by fortify
Insecure Web Application - .NET version
damn-vulnerable-MCP-server
by harishsg993010
Damn Vulnerable MCP Server
FridaMe
by CognisysGroup
FridaMe is intentionally vulnerable android application developed to demonstrate the usage of Frida.
Damn-vulnerable-sca
by harekrishnarai
Damn Vulnerable SCA Application
juice-shop
by juice-shop
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
vulhub
by vulhub
Pre-Built Vulnerable Environments Based on Docker-Compose
DVWA
by digininja
Damn Vulnerable Web Application (DVWA)
WebGoat
by WebGoat
WebGoat is a deliberately insecure application
kubernetes-goat
by madhuakula
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
cloudgoat
by RhinoSecurityLabs
CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool
VulnerableLightApp
by Aif4thah
Vulnerable API for research and education
dvta
by srini0x00
Damn Vulnerable Thick Client App developed in C# .NET
vulnerable-nginx
by detectify
An intentionally vulnerable NGINX setup
log-snare
by sea-erkin
LogSnare: A playground for testing, preventing, and logging IDOR vulnerabilities.
Infosec Certifications Resources
Discover the best cybersecurity certifications to advance your career








































Frequently Asked Questions about InfosecMania
Learn more about Cybersecurity Tools and how they can enhance your security posture
InfoSecMania is a comprehensive directory of cybersecurity tools and resources designed to help security professionals find the right tools for their needs.
You can submit a tool by clicking on the 'Submit Tool' link in the navigation menu and filling out the submission form with details about your tool.
No, InfoSecMania includes both free and commercial tools. Each tool listing indicates whether it's free, paid, or offers a freemium model.
Tools are categorized based on their primary function, such as penetration testing, vulnerability assessment, network security, etc. Many tools may appear in multiple categories if they serve multiple purposes.
We only list tools and resources from publicly available, reputable sources — most of which are open-source and widely used in the cybersecurity community. However, always review and test tools in a safe, legal environment, like your lab or VM.
We actively monitor public repositories, GitHub, and community forums to keep our tool listings fresh. Many tools are auto-sourced from open-source feeds and security communities.