
shannon
Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Source code for the Binaries of OWASP WrongSecrets

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Application Security Verification Standard

A vulnerable version of Rails that follows the OWASP Top 10

OWASP Foundation Web Respository

Given JSON-like content, The JSON Sanitizer converts it to valid JSON.

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Golang Secure Coding Practices guide

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

The Secure Coding Framework

MARA is a Mobile Application Reverse engineering and Analysis Framework. It is a toolkit that puts together commonly used mobile application reverse…