Skip to content
@SasanLabs

SasanLabs

No power on earth can stop an idea whose time has come.

Welcome to SasanLabs 🌱🔐✨

SasanLabs is an open-source educational platform for cybersecurity. Our goal is to make learning security practical, hands-on, and accessible to everyone.

We provide a modular ecosystem of labs and tools that help users explore real-world vulnerabilities, experiment with security concepts, and practice AI-driven security techniques.

  • ✅ Learn step-by-step how to exploit and secure vulnerabilities.
  • 🤖 Explore AI-based vulnerabilities in LLMForge.
  • 🛡️ Improve everyday security awareness with SAFE.

Our journey: image

We started by creating ZAP add-ons for security testing and quickly realized that building vulnerable apps for testing secuity tools was cumbersome. That inspired VulnerableApp, a lab where adding new vulnerabilities is easy. To support different tech stacks, we created a farm of vulnerable apps with a unified VulnerableApp-facade for simple orchestration. Later, we added LLM-based labs and SAFE, turning SasanLabs into a comprehensive educational platform for cybersecurity learners.

Whether you’re a developer, security enthusiast, or student, SasanLabs makes learning cybersecurity simple, practical, and fun. 🌿💡


Our Projects


Join Us

  • ⭐ Star our repos
  • 🛠 Contribute code or ideas
  • 💡 Learn, explore, and experiment

Security made simple. Learning made fun. Built to last.

Pinned Loading

  1. VulnerableApp VulnerableApp Public

    OWASP VulnerableApp Project: Break it. Scan it. Reproduce it. Benchmark against it. Improve it.

    Java 402 687

  2. VulnerableApp-facade VulnerableApp-facade Public

    VulnerableApp-facade is probably most modern lightweight distributed farm of Vulnerable Applications built for handling wide range of vulnerabilities across tech stacks.

    TypeScript 55 58

  3. LLMForge LLMForge Public

    LLMForge is a modular AI security gateway for building and testing dynamic LLM-based vulnerability labs. Designed for prompt injection research, exploit simulation, and AI attack experimentation.

    Python 5 2

  4. SAFE SAFE Public

    Security awareness for everyone

    2 1

  5. owasp-zap-jwt-addon owasp-zap-jwt-addon Public

    OWASP ZAP addon for finding vulnerabilities in JWT Implementations

    Java 36 12

  6. owasp-zap-fileupload-addon owasp-zap-fileupload-addon Public

    OWASP ZAP add-on for finding vulnerabilities in File Upload functionality.

    Java 24 4

Repositories

Showing 10 of 12 repositories

Top languages

Loading…

Most used topics

Loading…