
ftw
YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Structured curriculum for learning application security, covering secure coding, threat modeling, and DevSecOps practices. Designed for self-paced…

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Static web application for viewing SBOMs and performing on-demand vulnerability scanning with osv.dev. Easily deployable to GitHub/GitLab Pages.

A source code static analysis platform for AppSec enthusiasts.

Burp Extension for collaboration in Faraday

OWASP Security Culture repository

Hardening Script for Linux Servers/ Secure LAMP-LEMP Deployer/ CIS Benchmark

PoC for CVE-2026-22018, a critical Jenkins Pipeline Shared Library RCE via Groovy @Grab, demonstrating supply-chain code injection and mitigation…

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

InSpec-based compliance profile for auditing Linux system hardening against security baselines, ensuring consistent configuration across…

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets

Audits software supply chain security compliance against the CIS benchmark, scanning SCM settings, branch protections, dependencies, and CI/CD…

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

Gixy-Next: NGINX Configuration Security Scanner & Performance Checker

A privacy and security engineering toolkit: Discover, understand, pseudonymize, anonymize, encrypt and securely share sensitive and personal data:…

server security auditor scanning Apache, Nginx, and IIS configurations with AI-powered hardening guides and professional reporting.