


Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Industrial-grade C++ RPC framework for building high-performance distributed systems, supporting multiple protocols (HTTP, gRPC, Redis, Thrift) with…

Automatic SQL injection and database takeover tool

Your gateway to OWASP. Discover, engage, and help shape the future!

AI governance and evidence gateway for multi-provider LLM applications. FastAPI + optional Rust core for policy, WAF, egress, rate limits, sessions,…

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…

The Symfony PHP framework

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

cMCP: Confidential MCP Gateway. Hardware-attested policy enforcement for MCP tool calls.

An easy-to-use and lightweight API wrapper for Censys APIs.

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Knocker, a knock based access control service for your homelab

An empirical security testbed evaluating prompt injection, confused-deputy vulnerabilities, and tool-calling defenses in LLM agents.

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.