
discover
Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

CyberArk Security Audit

find sensitive data leaking from ServiceNow instances.

Vulnerability Assessment Scanner with Report Generation

GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

Spring Cloud Config CVE-2019-3799|CVE_2020_5410 漏洞检测

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

An open source threat modeling tool from OWASP

The source files and tools needed to build the OWASP Cornucopia decks in various languages

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

Vulnerable app with examples showing how to not use secrets


Security compliance platform - SOC2, CMMC, ASVS, ISO27001, HIPAA, NIST CSF, NIST 800-53, CSC CIS 18, PCI DSS, SSF tracking

Vendor-neutral OWASP project mapping quantum-era security risks with a Top 10 risk list, mitigation guidance, and threat models for post-quantum…