
noir
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Passive Laravel middleware that detects and logs SQL injection, XSS, RCE, bot scanners, and 175+ attack patterns. Features a built-in dashboard,…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Fast Go HTML sanitizer using an allowlist-based policy engine to scrub user-generated content of XSS and other injection attacks, inspired by OWASP…

Application Security Verification Standard

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Open-source API security platform that inventories endpoints, detects sensitive data, identifies and blocks malicious traffic in real time, and…

An open source threat modeling tool from OWASP

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Self-hostable API lab with OWASP API Top 10 vulnerability exercises. Includes Docker deployment, Postman collections, and walkthroughs for hands-on…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

OWASP Autonomous Penetration Testing Standard