
DockSec
AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Autonomous AI red team agent for penetration testing with 13+ specialized agents, 120+ OWASP test cases, and MITRE ATT&CK integration. Supports 15+…

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings,…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

Passive Laravel middleware that detects and logs SQL injection, XSS, RCE, bot scanners, and 175+ attack patterns. Features a built-in dashboard,…


Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis