The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
-
Updated
Mar 4, 2023 - Python
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
The OWASP ZAP core project
Web path scanner
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
A list of web application security
Next generation web scanner
w3af: web application attack and audit framework, the open source web vulnerability scanner.
Open Source Vulnerability Management Platform
Git All the Payloads! A collection of web attack payloads.
Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...
DefectDojo is a DevSecOps and vulnerability management tool.
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
The parent project for OpenZiti. Here you will find the executables for a fully zero trust, application embedded, programmable network
OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an easy-to-use web hacking environment designed for labs, security enthusiasts, classrooms, CTF, and vulnerability assessment tool targets.
A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.
vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.
Add a description, image, and links to the appsec topic page so that developers can more easily learn about it.
To associate your repository with the appsec topic, visit your repo's landing page and select "manage topics."