
Resources-for-Application-Security
Some good resources for getting started with application security

Some good resources for getting started with application security

Zed Attack Proxy Scripts for finding CVEs and Secrets.

A multi threaded Python script designed to brute force directories and files names on webservers.

Dockerized PHP application providing hands-on XSS vulnerability challenges and bypass examples, including WAF, blacklist, and JavaScript validation…

pytest for AI agents - Autonomous red-teaming, behavioral monitoring & security testing for LLM agents

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

An empirical security testbed evaluating prompt injection, confused-deputy vulnerabilities, and tool-calling defenses in LLM agents.

Open-source prompt injection attack console. Test AI security by firing categorized attacks at any endpoint.

A black-box (DAST) security analysis of CVE-2026-34835 focusing on external validation methodology, observable behavior, security impact, and…

Silent dependency injection through AI documentation pipelines. 240 isolated Docker runs proving Context Hub's zero-sanitization MCP server lets…

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

OWASP VBScan is a Black Box vBulletin Vulnerability Scanner

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how…

A vulnerable version of Rails that follows the OWASP Top 10

OWASP Autonomous Penetration Testing Standard

O-Saft - OWASP SSL advanced forensic tool

OWASP Vulnerable Web Application Project https://github.com/hummingbirdscyber