
PSCF
OWASP framework providing structured security capabilities for software products, derived from regulatory and industry standards analysis to guide…

OWASP framework providing structured security capabilities for software products, derived from regulatory and industry standards analysis to guide…

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

The Secure Coding Framework

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

End to End testing of Web, API, Cloud, Events and Security


YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Orchestration component of purpleteam


OWASP Security Culture repository

OWASP SecurityRAT (version 1.x) - Tool for handling security requirements in development

OWASP Kubernetes security and compliance tool [WIP]

OWASP teaching modules covering application security fundamentals including risk management, secure software development, and operations security for…

Automated Security Testing For REST API's

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…