
api-scanner-docker
Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

An open source threat modeling tool from OWASP

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

An empirical security testbed evaluating prompt injection, confused-deputy vulnerabilities, and tool-calling defenses in LLM agents.

Your gateway to OWASP. Discover, engage, and help shape the future!

OWASP Secure Agent Playbook Project

Application Security Verification Standard

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

Security standard for agent skills, providing guidelines and best practices to secure AI-driven autonomous agents in cloud and API environments.

OWASP Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input…