
crAPI
Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

An open source threat modeling tool from OWASP

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

OWASP Honeypot, Automated Deception Framework.

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

An empirical security testbed evaluating prompt injection, confused-deputy vulnerabilities, and tool-calling defenses in LLM agents.

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

OWASP Autonomous Penetration Testing Standard

Your gateway to OWASP. Discover, engage, and help shape the future!

OWASP Secure Agent Playbook Project

Application Security Verification Standard

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.