
mas-crackmes
The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.

The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.

OWASP Ontology-driven Threat Modelling framework

The OWASP Mobile Application Security Project website is the central hub for industry-leading standards, guides, and resources—helping developers and…

Source code for the Binaries of OWASP WrongSecrets

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

OWASP Learning Gateway Project

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava

Official repository for the AppSecDC 2019 conference, hosting presentation materials, resources, and curated content from the OWASP AppSecDC event.

Automated SBOM-to-VEX pipeline using a secure multi-agent AI system to analyze CVEs, reason about exploitability, and generate signed CycloneDX VEX…

OWASP Security Culture repository

OWASP top 10 security risks for audio and video communications, documenting common vulnerabilities and threats in modern real-time communication…

OWASP project defining an AI Bill of Materials (AIBOM) standard to document AI/ML components, dependencies, and supply chain risks for AI security…

OWASP Passfault evaluates passwords and enforces password policy in a completely different way.

Web and mobile application security training platform

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Getting a handle on container security

a Damn Vulnerable Serverless Application

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…