
cve-lite-cli
Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

Community-driven project providing guidance and resources to improve browser security, including best practices and educational materials for…

Application Security Verification Standard

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

Repo to hold mapping of user-security-stories

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

Project focused on governance and risk in application security, providing resources and frameworks for security maturity and risk management.

A documentation and tracking project with the goal of making package management systems more secure.

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

Structured curriculum for learning application security, covering secure coding, threat modeling, and DevSecOps practices. Designed for self-paced…

Coordination structure for AI security standards and guidelines, reducing fragmentation and providing clear guidance for securing AI systems across…




A practical framework identifying and prioritizing the top security risks in AI datacenter infrastructure, covering hardware, networking, management…

A curated library of security prompts for AI-assisted security testing, threat modeling, and educational exercises.

Curated collection of payloads for ethical security testing and bug bounty hunting, covering common web vulnerabilities and attack vectors.