
bunkerweb
🛡️ Open-source and cloud-native Web Application Firewall (WAF)

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Static web application for viewing SBOMs and performing on-demand vulnerability scanning with osv.dev. Easily deployable to GitHub/GitLab Pages.

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Hardening Script for Linux Servers/ Secure LAMP-LEMP Deployer/ CIS Benchmark

A source code static analysis platform for AppSec enthusiasts.

Forked from https://gitlab.alpinelinux.org/kaniini/secfixes-tracker

PoC for CVE-2026-22018, a critical Jenkins Pipeline Shared Library RCE via Groovy @Grab, demonstrating supply-chain code injection and mitigation…

Application scanning component of purpleteam

Stage two containers

Orchestration component of purpleteam

TLS checking component of purpleteam

Server scanning component of purpleteam

CLI component of purpleteam

YAML-driven CLI scanner that detects exposed services, files, and folders on web endpoints. Designed for developers to integrate security checks into…

Open Source Cloud Native Application Protection Platform (CNAPP)

Trigger-aware web server CVE audit for nginx and Apache. Goes beyond version matching by checking whether the vulnerable code path is actually…