
web-threat-mitigation
Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

An open source threat modeling tool from OWASP

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

OWASP Kubernetes security and compliance tool [WIP]

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

Vulnerable app with examples showing how to not use secrets

The Secure Coding Dojo is a platform for delivering secure coding knowledge.


OWASP SecurityRAT (version 1.x) - Tool for handling security requirements in development

Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with…

Executable security regression testing for agentic applications and MCP-integrated systems.


A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

Intelligent Component Analysis platform that leverages SBOMs to identify and reduce software supply chain risk through continuous vulnerability…