
beelzebub
A secure low code deception runtime framework, leveraging AI for System Virtualization.

A secure low code deception runtime framework, leveraging AI for System Virtualization.

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

A reverse proxy like nginx, built on pingora, simple and efficient.

OWASP Autonomous Penetration Testing Standard

Run Coding Agents in Sandboxes. Control Them Over HTTP. Supports Claude Code, Codex, OpenCode, and Amp.

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…

Cobalt Strike HTTPS beaconing over Microsoft Graph API

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.