
purple-team-exercise-framework
Purple Team Exercise Framework

Purple Team Exercise Framework

Slides for Developing Secure Software in 2024 at CanSecWest



A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

OWASP Security Culture repository


Repo to hold mapping of user-security-stories

OWASP teaching modules covering application security fundamentals including risk management, secure software development, and operations security for…

An open source threat modeling tool from OWASP

CVE-2025-53652: Jenkins Git Parameter Analysis

Security toolkit to detect CVE-2025-55182 (React2Shell) vulnerability

A GitHub Action to find Unicode control characters using the Red Hat diagnostic tool https://access.redhat.com/security/vulnerabilities/RHSB-2021-007…

Sean's Surf & Skate Co. — Spring Boot storefront with a vulnerable SnakeYAML dep (CVE-2022-1471) for Seal Security demos

.NET 7 fork of seal-security-nuget-demo: same CVE-2024-21907 exploit story, retargeted for customers locked to .NET SDK 7.

Seal Security example — vulnerable pip app (PyYAML CVE-2020-14343) remediated to sealed versions; GitHub Actions + Jenkins integration

OpsGuard eliminates the "3 AM PagerDuty" nightmare, specifically protecting against threats like the recent CVE-2025-55184 (Next.js DoS)