
gotestwaf
An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

OWASP Secure Agent Playbook Project


OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

A fast, simple, recursive content discovery tool written in Rust.

OPNsense GUI, API and systems backend

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

Damn Vulnerable MCP Server

Ephemeral microVM sandbox for AI agents with network allowlisting, secret injection via MITM proxy, and VM-level isolation. Boots in under a second,…

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

a PE Loader and Windows API tracer. Useful in malware analysis.

Lightweight file-based CLI API client with age-encrypted secrets, first-class GraphQL support and MCP server for agentic workflow.

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks.

POC for utilizing wikipedia API for Command and Control