
Astra
Automated Security Testing For REST API's

Automated Security Testing For REST API's

Some good resources for getting started with application security

A curated list of resources for learning about application security

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

The DevSecOps toolset for REST APIs

BoB Web Application Security Project

Open-source prompt injection attack console. Test AI security by firing categorized attacks at any endpoint.

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

Official OWASP Top 10 Document Repository

OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

Perl-based Joomla CMS vulnerability scanner automating version enumeration, component detection, exploit matching, firewall identification, and…

PHP-RBAC is an authorization library for PHP. It provides developers with NIST Level 2 Standard Role Based Access Control and more, in the fastest…

OWASP Serverless Top 10

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

OWASP Learning Gateway Project
