
Packer-Fuzzer
Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.

Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Web and mobile application security training platform

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

OWASP Web Recon & Directory Discovery Platform

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

AI security agent that runs in your terminal, orchestrating local tools, runbooks, and agents for authorized AppSec, pentest, OSINT, and CTF…

SSRF plugin for burp Automates SSRF Detection in all of the Request

Open-source adversary emulation for AI agents and MCP servers.

a Damn Vulnerable Serverless Application

The OWASP SecureTea Project provides a one-stop security solution for various devices (personal computers / servers / IoT devices)

Web app authorisation coverage scanning

BoB Web Application Security Project

This script communicates with the Nessus API in an attempt to help with automating scans. Depending on the flag issued with the script, you can list…

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

Automated authorization security scanner for OpenAPI-based APIs. Tests GET endpoints with multiple credential sets to detect privilege escalation and…