
pentest-guide
Penetration tests guide based on OWASP including test cases, resources and examples.

Penetration tests guide based on OWASP including test cases, resources and examples.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

SAML2 Burp Extension

OWASP Passfault evaluates passwords and enforces password policy in a completely different way.

DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

A documentation and tracking project with the goal of making package management systems more secure.

Burp Suite plugin for automated token extraction and replacement in HTTP requests, supporting JSON, XML, cookies, and URL parameters to streamline…

CyberArk Security Audit

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

This extension, for Burp Suite Enterprise Edition, utilizes session handling rules to provide a TOTP token to outgoing requests.

A proxy for net.tcp-based WCF traffic.

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.