
Bug_Bounty_writeups
Curated collection of bug bounty writeups covering OWASP Top 10 vulnerabilities, including XSS, SQLi, SSRF, and RCE, for educational learning and…

Curated collection of bug bounty writeups covering OWASP Top 10 vulnerabilities, including XSS, SQLi, SSRF, and RCE, for educational learning and…

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

OWASP IoT Security Verification Standard (ISVS)

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

German OWASP Day conference site & presentation archive

OWASP Security Culture repository

The most comprehensive LLM + MCP security guide i.e. OWASP aligned, real CVEs, actionable checklists

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

An open, vendor-neutral verification standard for traceable, reviewable, and rights-aware open-source intelligence. Current release: OOVS v0.1.0.

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

Software Component Verification Standard (SCVS)

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying…