
MASTG-Hacking-Playground
Collection of intentionally insecure iOS and Android apps for learning mobile security testing, reverse engineering, and vulnerability analysis,…

Collection of intentionally insecure iOS and Android apps for learning mobile security testing, reverse engineering, and vulnerability analysis,…

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

OWASP D4N155 - Intelligent and dynamic wordlist using OSINT

Hands-on AI security learning platform with intentionally vulnerable LLM applications. Explore OWASP Top 10 for LLMs through interactive pizza shop…

OWASP Secure Agent Playbook Project

This is a container of web applications that work with OWASP Bug Bounty for Projects

OWASP guide for security champions, providing curated resources and learning paths to foster security culture and practices within development teams.

The OWASP Mobile Application Security Project website is the central hub for industry-leading standards, guides, and resources—helping developers and…

OWASP SAPKiln is a graphical user interface (GUI) tool designed to facilitate securing and auditing SAP systems effectively.

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

OWASP Foundation Web Respository

Web and mobile application security training platform

a Damn Vulnerable Serverless Application

A deliberately vulnerable web application for learning web application security.

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

This is a defunct code base. The project is located at: https://github.com/WebGoat

Social engineering attack vector and exploitation framework for hijacking user sessions via QR code login, targeting web applications like WhatsApp,…