
coraza
Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

An open source threat modeling tool from OWASP

Passive Laravel middleware that detects and logs SQL injection, XSS, RCE, bot scanners, and 175+ attack patterns. Features a built-in dashboard,…

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

Your gateway to OWASP. Discover, engage, and help shape the future!

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

OWASP Autonomous Penetration Testing Standard

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

Application Security Verification Standard

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Structured OWASP-grounded security playbooks for AI agents. Enables automated code review, dependency CVE scanning, secrets detection, API security…

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

Security standard for agent skills, providing guidelines and best practices to secure AI-driven autonomous agents in cloud and API environments.