
Software-Component-Verification-Standard
Software Component Verification Standard (SCVS)

Software Component Verification Standard (SCVS)

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

Vulnerable app with examples showing how to not use secrets

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying…

VULNRΞPO - Free vulnerability report generator and repository, end-to-end encrypted! Templates of issues, CWE,CVE,MITRE ATT&CK,PCI DSS, import…

🧮 An online calculator to assess the risk of web vulnerabilities based on OWASP Risk Assessment

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

Open-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.

A black-box (DAST) security analysis of CVE-2026-34835 focusing on external validation methodology, observable behavior, security impact, and…

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

A collection of hacking / penetration testing resources to make you better!

Security compliance platform - SOC2, CMMC, ASVS, ISO27001, HIPAA, NIST CSF, NIST 800-53, CSC CIS 18, PCI DSS, SSF tracking

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

BoB Web Application Security Project

本项目通过大模型联动爬虫,检索Github上所有存有有价值漏洞信息与漏洞POC或规则信息的项目,并自动识别项目的目录结构、Readme信息后进行总结分析并分类,所汇总的项目可以帮助安全行业从业者收集漏洞信息、POC信息、规则等。

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Official OWASP Top 10 Document Repository

OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)