
CheatSheetSeries
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

OWASP Secure Agent Playbook Project

Application Security Verification Standard

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

An open source threat modeling tool from OWASP

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

OWASP Honeypot, Automated Deception Framework.

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

OWASP Autonomous Penetration Testing Standard

Your gateway to OWASP. Discover, engage, and help shape the future!

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.