
vapi
vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Executable security regression testing for agentic applications and MCP-integrated systems.

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

The most comprehensive LLM + MCP security guide i.e. OWASP aligned, real CVEs, actionable checklists

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

A collection of hacking / penetration testing resources to make you better!

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

Automated Security Testing For REST API's

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying…

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

VULNRΞPO - Free vulnerability report generator and repository, end-to-end encrypted! Templates of issues, CWE,CVE,MITRE ATT&CK,PCI DSS, import…

The DevSecOps toolset for REST APIs

Open-source adversary emulation for AI agents and MCP servers.

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

BoB Web Application Security Project