
test-certs-site
A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

A bash automation that exploits the vulnerable endpoints for the Joomla! API 4.0 - 4.2.7

Authenticated WordPress IDOR exploit for CVE-2026-12400; enumerates FlowForms REST form IDs and modifies form content or hijacks email notifications.

Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

Nacos下Spring-Cloud-Gateway CVE-2022-22947利用环境

Security compliance platform - SOC2, CMMC, ASVS, ISO27001, HIPAA, NIST CSF, NIST 800-53, CSC CIS 18, PCI DSS, SSF tracking

A program for testing WAF functionality

A proxy for net.tcp-based WCF traffic.

The AI toolkit for building reliable browser automations

The most comprehensive LLM + MCP security guide i.e. OWASP aligned, real CVEs, actionable checklists

Penetration tests guide based on OWASP including test cases, resources and examples.

OWASP Autonomous Penetration Testing Standard

AI security agent that runs in your terminal, orchestrating local tools, runbooks, and agents for authorized AppSec, pentest, OSINT, and CTF…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Self-hosted runtime control plane for AI agents. Observe or HITL approve or Block rogue tool calls before it executes: secret leaks, prompt…

Open-source prompt injection attack console. Test AI security by firing categorized attacks at any endpoint.

Open-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.