
threat-dragon
An open source threat modeling tool from OWASP

An open source threat modeling tool from OWASP

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

OWASP Kubernetes security and compliance tool [WIP]

Vulnerable app with examples showing how to not use secrets

OWASP SecurityRAT (version 1.x) - Tool for handling security requirements in development

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Executable security regression testing for agentic applications and MCP-integrated systems.


Open-Source Unified Vulnerability Management, DevSecOps & ASPM

Intelligent Component Analysis platform that leverages SBOMs to identify and reduce software supply chain risk through continuous vulnerability…

Automated Security Testing For REST API's

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

Security compliance platform - SOC2, CMMC, ASVS, ISO27001, HIPAA, NIST CSF, NIST 800-53, CSC CIS 18, PCI DSS, SSF tracking

The DevSecOps toolset for REST APIs

pytest for AI agents - Autonomous red-teaming, behavioral monitoring & security testing for LLM agents

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

CLI for generating, analyzing, merging, diffing, validating, signing, and converting CycloneDX SBOMs across JSON, XML, Protobuf, CSV, and SPDX…

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.