
SecurityShepherd
Web and mobile application security training platform

Web and mobile application security training platform

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Getting a handle on container security

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

This is a defunct code base. The project is located at: https://github.com/WebGoat

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Community-driven project providing guidance and resources to improve browser security, including best practices and educational materials for…

Application Security Verification Standard

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

Golang Secure Coding Practices guide


The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

pysap is an open source Python library that provides modules for crafting and sending packets using SAP's NI, Diag, Enqueue, Router, MS, SNC, IGS,…

Interactive platform linking security standards and guidelines for designing, developing, testing, and procuring secure software. Provides a unified…

Repo to hold mapping of user-security-stories

Project focused on governance and risk in application security, providing resources and frameworks for security maturity and risk management.

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…