
mastg
Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…


The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

The Secure Coding Practices Quick-reference Guide from OWASP

OWASP Thick Client Application Security Verification Standard

A vulnerable version of Rails that follows the OWASP Top 10

OWASP Secure Agent Playbook Project

OWASP Certified Secure-Software Developer

OWASP Smart Contract Security (SCS) Project

Source code for the Binaries of OWASP WrongSecrets

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava