
open-sammy
Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

The source files and tools needed to build the OWASP Cornucopia decks in various languages

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

Server scanning component of purpleteam

CLI component of purpleteam

Application scanning component of purpleteam

Stage two containers

TLS checking component of purpleteam

Orchestration component of purpleteam

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

An open source threat modeling tool from OWASP

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

OWASP Kubernetes security and compliance tool [WIP]

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

Vulnerable app with examples showing how to not use secrets

Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with…
