
Nest
Your gateway to OWASP. Discover, engage, and help shape the future!

Your gateway to OWASP. Discover, engage, and help shape the future!

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

This is a container of web applications that work with OWASP Bug Bounty for Projects

IoTGoat is a deliberately insecure firmware based on OpenWrt.

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

Automated Web Vulnerability Assessment of DVWA using OWASP ZAP to identify and analyze critical security flaws like Remote Code Execution…

The Secure Coding Practices Quick-reference Guide from OWASP

OWASP guide for security champions, providing curated resources and learning paths to foster security culture and practices within development teams.


A deliberately vulnerable web application for learning web application security.

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

The source files and tools needed to build the OWASP Cornucopia decks in various languages

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how…

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.