
awesome-appsec
A curated list of resources for learning about application security

A curated list of resources for learning about application security

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

Automated Security Testing For REST API's

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying…

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Twitter vulnerable snippets

The DevSecOps toolset for REST APIs

Open-source adversary emulation for AI agents and MCP servers.

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

BoB Web Application Security Project

Some good resources for getting started with application security

Zed Attack Proxy Scripts for finding CVEs and Secrets.

A multi threaded Python script designed to brute force directories and files names on webservers.

Dockerized PHP application providing hands-on XSS vulnerability challenges and bypass examples, including WAF, blacklist, and JavaScript validation…

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

Open-source prompt injection attack console. Test AI security by firing categorized attacks at any endpoint.

A black-box (DAST) security analysis of CVE-2026-34835 focusing on external validation methodology, observable behavior, security impact, and…

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions