
noir
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

Twitter vulnerable snippets

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

Open-source adversary emulation for AI agents and MCP servers.

The DevSecOps toolset for REST APIs

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

BoB Web Application Security Project

Some good resources for getting started with application security

Zed Attack Proxy Scripts for finding CVEs and Secrets.

Dockerized PHP application providing hands-on XSS vulnerability challenges and bypass examples, including WAF, blacklist, and JavaScript validation…

A multi threaded Python script designed to brute force directories and files names on webservers.

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

Open-source prompt injection attack console. Test AI security by firing categorized attacks at any endpoint.

A black-box (DAST) security analysis of CVE-2026-34835 focusing on external validation methodology, observable behavior, security impact, and…

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

OWASP VBScan is a Black Box vBulletin Vulnerability Scanner

Official OWASP Top 10 Document Repository