


Intentionally vulnerable machine learning model for hands-on security training. Explore common ML vulnerabilities, adversarial attacks, and defensive…

Advanced HTTP fingerprinting PoC

OWASP Thick Client Application Security Verification Standard

Official OWASP Top 10 Document Repository

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Damn Vulnerable C# Application (API)

Burp Suite extension to extract and collect GraphQL API endpoints from HTTP request history for security testing and reconnaissance.

Rust client library for the OWASP ZAP API, enabling programmatic access to web application security scanning, vulnerability detection, and proxy…

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

An HTTP client specifically developed for security researchers

Go client to communicate with Chaos DB API.

This is a container of web applications that work with OWASP Bug Bounty for Projects

A deliberately vulnerable web application for learning web application security.

A documentation and tracking project with the goal of making package management systems more secure.

OWASP framework providing structured security capabilities for software products, derived from regulatory and industry standards analysis to guide…