
owasp-ctf-in-a-box
Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

An open source threat modeling tool from OWASP

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

OWASP Kubernetes security and compliance tool [WIP]

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

Vulnerable app with examples showing how to not use secrets

The Secure Coding Dojo is a platform for delivering secure coding knowledge.


OWASP SecurityRAT (version 1.x) - Tool for handling security requirements in development

Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with…

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Executable security regression testing for agentic applications and MCP-integrated systems.


A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

Intelligent Component Analysis platform that leverages SBOMs to identify and reduce software supply chain risk through continuous vulnerability…

Automated Security Testing For REST API's