
CheatSheetSeries
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

agent runtime security - zero trust, zero setup, zero latency.

Searches through git repositories for high entropy strings and secrets, digging deep into commit history

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Pluggable linting tool to prevent committing credential.

OWASP Secure Agent Playbook Project

OWASP Certified Secure-Software Developer

Using Struts2 and PowerShell to recreate CVE-2017-5638 OGNL Injection vulnerability.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

Apache RAT (Release Audit Tool) Gradle Plugin

CodeQL detector for CVE-2022-2869 root cause (CWE-191 unsigned underflow) using control-flow/range analysis to identify vulnerable patterns without…

Unofficial revival of the well known .NET debugger and assembly editor, dnSpy

Project Wycheproof tests crypto libraries against known attacks.

OWASP Smart Contract Security (SCS) Project

Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector

CVE-2022-31626, CVE-2024-2961, CVE-2019-6977, PHP security research