
OWASP-MCP-Threat-Modeling
OWASP tool for systematic threat modeling using the Model Context Protocol to identify and mitigate security risks in software architecture.

OWASP tool for systematic threat modeling using the Model Context Protocol to identify and mitigate security risks in software architecture.

Free security-baseline rule for Claude Code, Codex, and Cursor: treats MCP tool descriptions as untrusted input (OWASP MCP Top 10 MCP03,…

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

OWASP guide for security champions, providing curated resources and learning paths to foster security culture and practices within development teams.

Hands-on AI security learning platform with intentionally vulnerable LLM applications. Explore OWASP Top 10 for LLMs through interactive pizza shop…

Structured curriculum for learning application security, covering secure coding, threat modeling, and DevSecOps practices. Designed for self-paced…

A curated list of resources for learning about application security

OWASP top 10 security risks for audio and video communications, documenting common vulnerabilities and threats in modern real-time communication…

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

OWASP framework providing structured security capabilities for software products, derived from regulatory and industry standards analysis to guide…

Community-driven project providing guidance and resources to improve browser security, including best practices and educational materials for…

OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)

Some good resources for getting started with application security

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

Vendor-neutral OWASP project mapping quantum-era security risks with a Top 10 risk list, mitigation guidance, and threat models for post-quantum…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Curated collection of bug bounty writeups covering OWASP Top 10 vulnerabilities, including XSS, SQLi, SSRF, and RCE, for educational learning and…

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…