
RiskAssessmentFramework
The Secure Coding Framework

The Secure Coding Framework

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Penetration tests guide based on OWASP including test cases, resources and examples.

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

A collection of hacking / penetration testing resources to make you better!

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Official OWASP Top 10 Document Repository

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Intelligent Component Analysis platform that leverages SBOMs to identify and reduce software supply chain risk through continuous vulnerability…

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

Application Security Verification Standard

Hackable HTTP proxy for resiliency testing and simulated network conditions

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.