
waf-checker
Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Automated pentest reporting with custom templates, project tracking, customer dashboard and client management tools. Streamline your security…

Module-based web vulnerability scanner and bug bounty automation framework with built-in XSS, SSTI, SSRF, and Firebase detection engines. Designed to…

The SpecterOps project management and reporting engine

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

OWASP Secure Agent Playbook Project

Linux operating system for embedded devices with writable filesystem, package management, and build framework. Enables custom firmware creation for…

Educational security research repository documenting CVE-2026-65660 with setup guidance for authorized lab testing and vulnerability awareness.

Using Struts2 and PowerShell to recreate CVE-2017-5638 OGNL Injection vulnerability.

Monitoring the Cloud Landscape

OWASP hands-on Android security training lab with 78 MASVS/MASTG modules pairing vulnerable, secure, and attacker apps to demonstrate mobile…

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

The Browser Exploitation Framework Project

Collects Azure tenant data (users, groups, roles, resources) and exports it for BloodHound attack path analysis in cloud penetration testing and red…

A curated list of cybersecurity tools and resources.

PoC exploit and scanner for CVE-2026-89026, validating the Issabel PBXAPI authentication bypass via forged HS256 JWTs across single or listed targets.

The OWASP Mobile Application Security Project website is the central hub for industry-leading standards, guides, and resources—helping developers and…

Proof-of-concept and educational research repository for CVE-2026-74469 (DiagSpill), providing vulnerability analysis material for authorized lab…