
ai-tool-poisoning-guard
Free security-baseline rule for Claude Code, Codex, and Cursor: treats MCP tool descriptions as untrusted input (OWASP MCP Top 10 MCP03,…

Free security-baseline rule for Claude Code, Codex, and Cursor: treats MCP tool descriptions as untrusted input (OWASP MCP Top 10 MCP03,…

A structured knowledge base covering AI security fundamentals, threat modeling, red team offensive techniques, and blue team defenses, including LLM…

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

AI IR Overlay™ — practical incident response framework for AI agents in production. Built on NIST SP 800-61 r3, mapped to NIST AI RMF, NIST CSF 2.0,…

A practical framework identifying and prioritizing the top security risks in AI datacenter infrastructure, covering hardware, networking, management…

A wordlist of API names for web application assessments

This repository contains indicators of compromise (IOCs) of our various investigations.

Slides and materials from conference presentations

A curated knowledge base to build, run and mature a SOC (including CSIRT).

TOP All bugbounty pentesting CVE-2023- POC Exp RCE example payload Things


Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

OWASP top 10 security risks for audio and video communications, documenting common vulnerabilities and threats in modern real-time communication…

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

OWASP Serverless Top 10

Official OWASP Top 10 Document Repository
