
arachni
Web Application Security Scanner Framework

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Web application security scanner created by lcamtuf for google - Unofficial Mirror

Real-time web application weakness monitoring SDK and scanner. Detects XSS, SQL injection, sensitive payloads, and code vulnerabilities via dynamic…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Evidence first autonomous web security testing for controlled, authorized targets. With reproducible labs, audit trails, reports, and XBEN…

Stage two containers

This Python application scans for the CVE-2023-38831 vulnerability in WinRAR.

iblessing is an iOS security exploiting toolkit, it mainly includes application information gathering, static analysis and dynamic analysis. It can…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…

A curated list of awesome iOS application security resources.

Some good resources for getting started with application security

Static and dynamic Android application security analysis

Collaborative application security testing between humans and agents via CLI and MCP

The Python Version of our Not Go-ing Anywhere Vulnerable Application

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…