
AWSGoat
Intentionally vulnerable AWS infrastructure for practicing cloud penetration testing, covering OWASP Top 10 web risks, IAM, S3, Lambda, EC2, and ECS…

Intentionally vulnerable AWS infrastructure for practicing cloud penetration testing, covering OWASP Top 10 web risks, IAM, S3, Lambda, EC2, and ECS…

Intentionally vulnerable Azure infrastructure for practicing cloud penetration testing, red teaming, and secure coding. Features OWASP Top 10 web…

Curated list and specification for eliminating high-impact attack paths across cloud, identity, network, and container environments, aligned with the…

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

Hands-on lab for the OWASP Top 10 for LLM Applications (2025) with rule-based challenges, payload editor, and progressive hints. No real LLM required.

Perl-based Joomla CMS vulnerability scanner automating version enumeration, component detection, exploit matching, firewall identification, and…

OWASP-curated guide to the top 10 proactive security controls for Docker and containerized environments, covering threat modeling, configuration…

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Open-source CLI for static application security testing (SAST) of custom ABAP code. Scans exported source offline for injection, path-traversal, and…

Finds internet-exposed resources in an AWS account

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

50+ detectors across 10 categories, with continuous monitoring built in: schedule recurring scans, get alerted only on new findings, track your…

Automated AWS subdomain takeover detection tool using Terraform and serverless functions. Scans DNS records for dangling CNAMEs and alerts on…

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Enterprise WAF evaluation tool that sends 90 real attack payloads across 6 suites (OWASP, API, bypass, rate limiting) and generates compliance-ready…

Penetration tests guide based on OWASP including test cases, resources and examples.