
OWASP-MCP-Threat-Modeling
OWASP tool for systematic threat modeling using the Model Context Protocol to identify and mitigate security risks in software architecture.

OWASP tool for systematic threat modeling using the Model Context Protocol to identify and mitigate security risks in software architecture.

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

OWASP top 10 security risks for audio and video communications, documenting common vulnerabilities and threats in modern real-time communication…

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)

Vendor-neutral OWASP project mapping quantum-era security risks with a Top 10 risk list, mitigation guidance, and threat models for post-quantum…

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

The most comprehensive LLM + MCP security guide i.e. OWASP aligned, real CVEs, actionable checklists

Centralized YAML-based knowledge base linking MITRE CWE, OWASP Top10, ASVS, and other security standards with versioned references. Includes MkDocs…

MAPS cloud scanner and response parser for Microsoft Defender research.

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Coordination structure for AI security standards and guidelines, reducing fragmentation and providing clear guidance for securing AI systems across…

AI IR Overlay™ — practical incident response framework for AI agents in production. Built on NIST SP 800-61 r3, mapped to NIST AI RMF, NIST CSF 2.0,…

Interactive platform linking security standards and guidelines for designing, developing, testing, and procuring secure software. Provides a unified…

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

Structured playbook for integrating threat modeling into product security, covering stakeholder buy-in, organizational embedding, training, process…

An open, vendor-neutral verification standard for traceable, reviewable, and rights-aware open-source intelligence. Current release: OOVS v0.1.0.

German OWASP Day conference site & presentation archive