
OdTM
OWASP Ontology-driven Threat Modelling framework

OWASP Ontology-driven Threat Modelling framework

OWASP project defining an AI Bill of Materials (AIBOM) standard to document AI/ML components, dependencies, and supply chain risks for AI security…

The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.

Source code for the Binaries of OWASP WrongSecrets

Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

OWASP framework providing structured security capabilities for software products, derived from regulatory and industry standards analysis to guide…

OWASP Learning Gateway Project

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava

Official repository for the AppSecDC 2019 conference, hosting presentation materials, resources, and curated content from the OWASP AppSecDC event.

Automated SBOM-to-VEX pipeline using a secure multi-agent AI system to analyze CVEs, reason about exploitability, and generate signed CycloneDX VEX…

OWASP Security Culture repository

Centralized YAML-based knowledge base linking MITRE CWE, OWASP Top10, ASVS, and other security standards with versioned references. Includes MkDocs…

OWASP top 10 security risks for audio and video communications, documenting common vulnerabilities and threats in modern real-time communication…

OWASP tool for systematic threat modeling using the Model Context Protocol to identify and mitigate security risks in software architecture.

OWASP teaching modules covering application security fundamentals including risk management, secure software development, and operations security for…

OWASP hands-on Android security training lab with 78 MASVS/MASTG modules pairing vulnerable, secure, and attacker apps to demonstrate mobile…