
TCASVS
OWASP Thick Client Application Security Verification Standard

OWASP Thick Client Application Security Verification Standard

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

OWASP Secure Agent Playbook Project

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

OWASP Honeypot, Automated Deception Framework.

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

An open, vendor-neutral verification standard for traceable, reviewable, and rights-aware open-source intelligence. Current release: OOVS v0.1.0.

The most comprehensive LLM + MCP security guide i.e. OWASP aligned, real CVEs, actionable checklists

Open-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.

OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)

German OWASP Day conference site & presentation archive

OWASP Ontology-driven Threat Modelling framework

OWASP top 10 security risks for audio and video communications, documenting common vulnerabilities and threats in modern real-time communication…

OWASP Security Culture repository


Interactive platform linking security standards and guidelines for designing, developing, testing, and procuring secure software. Provides a unified…