Human Risk covers the tools built around a fact most security programs underweight: people are part of your attack surface, not just the systems they touch. The category spans Security Awareness Training, Phishing Simulation, the broader Human Risk Management platforms that score and segment workforce risk, Insider Threat Detection, User and Entity Behavior Analytics, and Cyber Range Training for hands-on practice by security staff. CISOs land here when annual compliance training stops moving the needle, or when they need to separate a careless click from a malicious insider. Most breaches still begin with a human action, so the work is measuring that risk, shifting behavior, and catching the moment intent turns hostile.
We cover 454 Human Risk tools, 117 free and 337 commercial.
Accuracy and depth improve over time. Last reviewed Sep 2026. Is something off? Reach out.
New to this category? What is Human Risk?
OVAA is an intentionally vulnerable Android application that aggregates common platform security vulnerabilities for educational and security testing purposes.
InsecureShop is an intentionally vulnerable Android application built in Kotlin for educating developers and security professionals about mobile app vulnerabilities and penetration testing techniques.
BlueTeam.Lab provides Terraform and Ansible scripts to deploy an orchestrated detection laboratory for testing attacks and forensic artifacts in a SOC-like Windows environment.
MockSSH is a testing tool that emulates operating systems behind SSH servers to enable automation testing without requiring access to real servers.
A Terraform tool that creates intentionally misconfigured AWS infrastructure with 84 vulnerabilities across 22 services for security training and testing purposes.
Root the Box is a real-time CTF scoring engine that provides a configurable platform for cybersecurity training through gamified wargames and competitions.
A comprehensive collection of free online laboratories and platforms for practicing penetration testing, CTF challenges, and cybersecurity skills development.
HackTheArch is an open-source Ruby on Rails-based scoring server platform designed for hosting and managing Cyber Capture the Flag competitions with web-based problem management and hint systems.
Intentionally vulnerable Kubernetes cluster environment for learning and practicing Kubernetes security.
CTFd is a web-based framework for creating and managing Capture The Flag cybersecurity competitions with customizable challenges, scoring systems, and team management capabilities.
A deliberately vulnerable web application that uses WebSocket communication to provide a training environment for learning about WebSocket-related security vulnerabilities.
AzureGoat is a deliberately vulnerable Azure cloud infrastructure that incorporates OWASP Top 10 vulnerabilities and Azure service misconfigurations for security training and penetration testing practice.
A project providing a low-cost ICS testbed with affordable hardware, instructions, and attacker scenarios to facilitate learning in industrial security.
A Windows kernel driver intentionally designed with various vulnerabilities to help security researchers practice kernel exploitation techniques.
FBCTF is a platform for hosting Jeopardy and King of the Hill style Capture the Flag competitions with support for various scales and participation models.
echoCTF is a cybersecurity framework for running Capture the Flag competitions and training exercises on real IT infrastructure.
A deliberately vulnerable GraphQL application designed for security testing and educational purposes, containing multiple intentional flaws for learning GraphQL attack and defense techniques.
GRFICS is a Unity 3D-based framework that provides a virtual industrial control system environment for practicing ICS security attacks and defenses with visual feedback.
InsecureBankv2 is an intentionally vulnerable Android application with a Python back-end server designed for educational purposes in mobile security testing and Android vulnerability research.
A deliberately vulnerable PHP/MySQL web application designed for security training, testing, and educational purposes in controlled environments.
DVXTE is a Docker-based training platform containing multiple vulnerable applications designed for cybersecurity education and skill development.
A collection of vulnerable web applications containing command injection flaws designed to test and evaluate detection and exploitation tools like commix.
DetectionLab is a pre-configured Windows domain environment with security tooling and logging designed for cybersecurity training and detection capability development.
454 tools across 6 specializations · 117 free, 337 commercial
Insider Threat Detection
Insider threat detection tools that monitor user behavior and identify potential insider risks and malicious activities.
Phishing Simulation
Phishing simulation platforms for testing employee susceptibility to phishing attacks and social engineering awareness.
Security Awareness Training
Cybersecurity awareness training content, LMS, and computer-based training for educating employees about security best practices.
Common questions about Human Risk tools, selection guides, pricing, and comparisons.
Human risk management is the practice of measuring, reducing, and monitoring the security risk that originates with people inside an organization. It connects awareness training, phishing simulation, behavioral signals, and insider threat detection into a single view of which employees, roles, or departments are most likely to cause an incident, then directs effort where it matters most instead of treating the whole workforce identically.
Security awareness training is one slice of the wider Human Risk category. Training and phishing simulation work to change behavior before something goes wrong. Human Risk Management platforms add scoring and segmentation on top, while Insider Threat Detection and UEBA catch risky or malicious activity in motion. Many buyers begin with training and grow into platforms that stitch all these signals together.
Often not. User and Entity Behavior Analytics is frequently the engine under insider threat detection: it baselines normal activity and flags anomalies like unusual data access or off-hours transfers. Some insider threat products embed UEBA directly, while others expect you to feed them signals from a SIEM or DLP. Confirm whether a tool detects the behavior itself or relies on another system to surface it.
Anchor on the outcome you need: behavior change, risk scoring, or threat detection. For training and phishing, weigh content quality, localization, and whether reporting maps to measurable risk reduction rather than completion rates. For detection tools, scrutinize data sources, false-positive rates, and privacy controls. Verify integrations with your identity provider, email, and SIEM, and that reporting holds up in front of leadership.
User and Entity Behavior Analytics
User and Entity Behavior Analytics (UEBA) tools that detect anomalous user activities and potential security threats through behavioral analysis.