
argumentinjectionhammer
A Burp Extension designed to identify argument injection vulnerabilities.

A Burp Extension designed to identify argument injection vulnerabilities.

Automated detection of vulnerable domain configurations and subdomain takeover risks across cloud environments, with continuous monitoring and…

OWASP Domain Protect - prevent subdomain takeover

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Rust client library for the OWASP ZAP API, enabling programmatic access to web application security scanning, vulnerability detection, and proxy…

A program for testing WAF functionality

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

The dependency-check repository has moved:

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

GCPGoat : A Damn Vulnerable GCP Infrastructure

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

OWASP SAPKiln is a graphical user interface (GUI) tool designed to facilitate securing and auditing SAP systems effectively.

OWASP VBScan is a Black Box vBulletin Vulnerability Scanner

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Web application penetration testing lab — vulnerable Flask app, automated scanner, and professional pentest report. Covers OWASP Top 10, SQLi, XSS,…

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…