
OWASP-Subtractive-Hardening-Top-10
Curated list and specification for eliminating high-impact attack paths across cloud, identity, network, and container environments, aligned with the…

Curated list and specification for eliminating high-impact attack paths across cloud, identity, network, and container environments, aligned with the…

Azure Sentinel detection lab for MCP attack patterns, providing 5 analytics rules and 7 KQL hunting queries against SSRF token theft, tool poisoning,…

The most comprehensive LLM + MCP security guide i.e. OWASP aligned, real CVEs, actionable checklists

A curated list of resources for learning about application security

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

Silent dependency injection through AI documentation pipelines. 240 isolated Docker runs proving Context Hub's zero-sanitization MCP server lets…

Official OWASP Top 10 Document Repository

Vendor-neutral OWASP project mapping quantum-era security risks with a Top 10 risk list, mitigation guidance, and threat models for post-quantum…

OWASP enumeration of common security and privacy weaknesses in mobile applications, serving as a reference bridging the MASVS verification standard…

Conference website and presentation archive for the German OWASP Day, hosting slides and resources from past security talks and workshops.

OWASP Smart Contract Security (SCS) Project

OWASP Ontology-driven Threat Modelling framework

OWASP framework providing structured security capabilities for software products, derived from regulatory and industry standards analysis to guide…

Automated SBOM-to-VEX pipeline using a secure multi-agent AI system to analyze CVEs, reason about exploitability, and generate signed CycloneDX VEX…

Centralized YAML-based knowledge base linking MITRE CWE, OWASP Top10, ASVS, and other security standards with versioned references. Includes MkDocs…

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

Coordination structure for AI security standards and guidelines, reducing fragmentation and providing clear guidance for securing AI systems across…