
Resources-for-Application-Security
Some good resources for getting started with application security

Some good resources for getting started with application security

Deliberately vulnerable Flask web application with 22 security flaws across 3 difficulty levels for hands-on penetration testing and web security…

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Web application penetration testing lab — vulnerable Flask app, automated scanner, and professional pentest report. Covers OWASP Top 10, SQLi, XSS,…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

A Web Vulnerability Scanner and Patcher

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Web vulnerability scanner built with C++17 and Qt 6, featuring a GUI, CLI, configurable crawling, and JSON reports. Reconstructed for educational…


Comprehensive open-source book on SELinux covering kernel components, userspace libraries, policy toolchain, and policy language. Includes build…

Comprehensive set of over 1500 AppArmor profiles to confine Linux system processes, desktops, and services, with support for multiple distributions…

A vulnerable version of Rails that follows the OWASP Top 10

This demo application partially covers the vulnerability CVE-2024-38828

intentionally vuln web Application Security in django

Educational environment for LTAT.04.022 Homework 4.

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…