
Nettacker
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

The source files and tools needed to build the OWASP Cornucopia decks in various languages

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

Server scanning component of purpleteam

CLI component of purpleteam

Application scanning component of purpleteam

Stage two containers

TLS checking component of purpleteam

Orchestration component of purpleteam

Regex-based malicious traffic detection add-on for OWASP ZAP. Flags compromised websites by matching URI and HTML patterns, with color-coded alerts…

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.


Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

An open source threat modeling tool from OWASP