
secure-coding-practices-quick-reference-guide
The Secure Coding Practices Quick-reference Guide from OWASP

The Secure Coding Practices Quick-reference Guide from OWASP

OWASP guide for security champions, providing curated resources and learning paths to foster security culture and practices within development teams.

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

OWASP hands-on Android security training lab with 78 MASVS/MASTG modules pairing vulnerable, secure, and attacker apps to demonstrate mobile…

The most comprehensive LLM + MCP security guide i.e. OWASP aligned, real CVEs, actionable checklists

*This project is no longer maintained* OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and…

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite.

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

Some good resources for getting started with application security

Repo to hold mapping of user-security-stories

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

Structured evaluation criteria framework for assessing Web Application Firewalls (WAFs), enabling users, vendors, and third parties to compare…

Structured playbook for integrating threat modeling into product security, covering stakeholder buy-in, organizational embedding, training, process…