
KubeLight
OWASP Kubernetes security and compliance tool [WIP]

OWASP Kubernetes security and compliance tool [WIP]

OWASP Thick Client Application Security Verification Standard

Community-driven framework defining activities, controls, and best practices to identify and reduce risk in software supply chains, with incremental…

Security compliance platform - SOC2, CMMC, ASVS, ISO27001, HIPAA, NIST CSF, NIST 800-53, CSC CIS 18, PCI DSS, SSF tracking

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

OWASP-curated guide to the top 10 proactive security controls for Docker and containerized environments, covering threat modeling, configuration…

Community-driven security requirements standard for IoT ecosystems, covering hardware, software, embedded applications, and communication protocols…

Git pre-receive hook that scans incoming commits for hard-coded credentials and sensitive data using customizable regex patterns, preventing leaks…

A documentation and tracking project with the goal of making package management systems more secure.

GUI tool for automated security auditing and penetration testing of SAP systems via SAP Logon/GUI, with 70+ checks across 10 modules including…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Multi-VM virtual network lab with GRE tunneling, nftables firewall, Active Directory, BIND9 DNS, and Docker services. Includes vulnerability…

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Remote PowerShell-based security audit tool for CyberArk PAM platforms. Performs CIS benchmark compliance, CVE checks, blackbox testing, and network…

Vulnerability Assessment Scanner with Report Generation

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

Spring Cloud Config CVE-2019-3799|CVE_2020_5410 漏洞检测