
wstg
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

The source files and tools needed to build the OWASP Cornucopia decks in various languages

Host and manage multiple Juice Shop instances for security trainings and Capture The Flags

Open-source MITM proxy to intercept, inspect, and mock network traffic.

Autonomous AI red team agent for penetration testing with 13+ specialized agents, 120+ OWASP test cases, and MITRE ATT&CK integration. Supports 15+…

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

An open source threat modeling tool from OWASP

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Automated REST API fuzzer and negative testing tool for OpenAPI endpoints. Generates, runs, and reports thousands of self-healing tests with no…

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Hands-on AI security learning platform with intentionally vulnerable LLM applications. Explore OWASP Top 10 for LLMs through interactive pizza shop…