
slinger
An HTTP client specifically developed for security researchers

An HTTP client specifically developed for security researchers

ExtendedMacro - BurpSuite plugin providing extended macro functionality

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

Minimal PoC and Docker container demonstrating a WAF bypass in OWASP ModSecurity CRS via multipart charset handling, leading to XSS payload delivery.

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…

Reproducer for CVE-2026-48206: Apache Camel camel-jira IssueKey (and other non-Camel-prefixed) header injection driving arbitrary JIRA issue…

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

Martian is a library for building custom HTTP/S proxies

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

This project is about creating and publishing threat model examples.


OWASP D4N155 - Intelligent and dynamic wordlist using OSINT

A OWASP Based Checklist With 80+ Test Cases