
owasp-java-encoder
The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

OWASP Learning Gateway Project

OWASP Security Culture repository

OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

Structured playbook for integrating threat modeling into product security, covering stakeholder buy-in, organizational embedding, training, process…

Repo to hold mapping of user-security-stories

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

OWASP Vulnerable Web Application Project https://github.com/hummingbirdscyber

Structured evaluation criteria framework for assessing Web Application Firewalls (WAFs), enabling users, vendors, and third parties to compare…

This is a defunct code base. The project is located at: https://github.com/WebGoat

Alexa skill example for Faraday API

A vulnerable version of Rails that follows the OWASP Top 10

Interactive platform linking security standards and guidelines for designing, developing, testing, and procuring secure software. Provides a unified…

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

OWASP guide for security champions, providing curated resources and learning paths to foster security culture and practices within development teams.

OWASP teaching modules covering application security fundamentals including risk management, secure software development, and operations security for…