
vuln-scanner
Vulnerability Assessment Scanner with Report Generation

Vulnerability Assessment Scanner with Report Generation

Burp Extension for collaboration in Faraday

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

The Secure Coding Framework

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

OWASP framework providing structured security capabilities for software products, derived from regulatory and industry standards analysis to guide…

OWASP Security Culture repository

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

Automated testing suite with live traffic record and replay

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)


A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with…

Open-Source Unified Vulnerability Management, DevSecOps & ASPM