
MARA_Framework
MARA is a Mobile Application Reverse engineering and Analysis Framework. It is a toolkit that puts together commonly used mobile application reverse…

MARA is a Mobile Application Reverse engineering and Analysis Framework. It is a toolkit that puts together commonly used mobile application reverse…

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

OWASP Vulnerable Web Application Project https://github.com/hummingbirdscyber

OWASP IoT Security Verification Standard (ISVS)

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

German OWASP Day conference site & presentation archive

OWASP Security Culture repository

The most comprehensive LLM + MCP security guide i.e. OWASP aligned, real CVEs, actionable checklists

An installable desktop variant of OWASP Threat Dragon

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

An open source threat modeling tool from OWASP

Executable security regression testing for agentic applications and MCP-integrated systems.