
nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

Penetration tests guide based on OWASP including test cases, resources and examples.

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

Perl-based Joomla CMS vulnerability scanner automating version enumeration, component detection, exploit matching, firewall identification, and…

AzureGoat : A Damn Vulnerable Azure Infrastructure

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Getting a handle on container security

GCPGoat : A Damn Vulnerable GCP Infrastructure

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

OWASP Domain Protect - prevent subdomain takeover

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

Academic purposes only. Attack against Salesforce lightning with guest privilege.

Automated CORS misconfiguration scanner that tests Origin header injection, wildcard reflection, and credential leakage across web applications and…


AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.