
HybridTestFramework
End to End testing of Web, API, Cloud, Events and Security

End to End testing of Web, API, Cloud, Events and Security

OWASP Ontology-driven Threat Modelling framework

AI IR Overlay™ — practical incident response framework for AI agents in production. Built on NIST SP 800-61 r3, mapped to NIST AI RMF, NIST CSF 2.0,…

Orchestration component of purpleteam

OWASP Kubernetes security and compliance tool [WIP]

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

OWASP IoT Security Verification Standard (ISVS)

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

a Damn Vulnerable Serverless Application

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

CyberArk Security Audit

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

PoC + analysis for CVE-2026-54917 — SeaweedFS S3 gateway cross-bucket path traversal (CVSS 10.0, <4.30). Read/write any bucket via .. in the object…

CLI component of purpleteam

Server scanning component of purpleteam

Application scanning component of purpleteam

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…