
apicheck
Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…

Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…

Deliberately vulnerable Docker lab with a routable DNS estate and machine-readable answer keys per target, scoring scanner precision, recall and…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

An open source threat modeling tool from OWASP

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

OWASP Kubernetes security and compliance tool [WIP]

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

Vulnerable app with examples showing how to not use secrets

The Secure Coding Dojo is a platform for delivering secure coding knowledge.


OWASP SecurityRAT (version 1.x) - Tool for handling security requirements in development

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with…

Executable security regression testing for agentic applications and MCP-integrated systems.


A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

Intelligent Component Analysis platform that leverages SBOMs to identify and reduce software supply chain risk through continuous vulnerability…