
API-Security
OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

OWASP Autonomous Penetration Testing Standard

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

pysap is an open source Python library that provides modules for crafting and sending packets using SAP's NI, Diag, Enqueue, Router, MS, SNC, IGS,…

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

Interactive platform linking security standards and guidelines for designing, developing, testing, and procuring secure software. Provides a unified…

OWASP Serverless Top 10

A documentation and tracking project with the goal of making package management systems more secure.

OWASP Ontology-driven Threat Modelling framework

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

This project is about creating and publishing threat model examples.

Getting a handle on container security

a Damn Vulnerable Serverless Application

