
java-html-sanitizer
Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.


AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

AzureGoat : A Damn Vulnerable Azure Infrastructure

GCPGoat : A Damn Vulnerable GCP Infrastructure

Penetration tests guide based on OWASP including test cases, resources and examples.

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

Automated detection of vulnerable domain configurations and subdomain takeover risks across cloud environments, with continuous monitoring and…

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

Perl-based Joomla CMS vulnerability scanner automating version enumeration, component detection, exploit matching, firewall identification, and…

OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

Getting a handle on container security

Finds internet-exposed resources in an AWS account