
FIASSE
A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

A collection of awesome resources related AI security

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Twitter vulnerable snippets

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

OWASP framework providing structured security capabilities for software products, derived from regulatory and industry standards analysis to guide…

OWASP Ontology-driven Threat Modelling framework

Curated collection of bug bounty writeups covering OWASP Top 10 vulnerabilities, including XSS, SQLi, SSRF, and RCE, for educational learning and…

AI IR Overlay™ — practical incident response framework for AI agents in production. Built on NIST SP 800-61 r3, mapped to NIST AI RMF, NIST CSF 2.0,…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

OWASP Thick Client Application Security Verification Standard

OWASP Autonomous Penetration Testing Standard

OWASP Serverless Top 10

Software Component Verification Standard (SCVS)

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

A OWASP Based Checklist With 80+ Test Cases