
passfault
OWASP Passfault evaluates passwords and enforces password policy in a completely different way.

Orchestration component of purpleteam

This project is about creating and publishing threat model examples.

OWASP Domain Protect - prevent subdomain takeover

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

A modern vulnerable web app

Python API security testing tool from OpenStack Security Group

File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

REST/JSON API to the Burp Suite security tool.

Research on GraphQL from an AppSec point of view.

OWASP VBScan is a Black Box vBulletin Vulnerability Scanner

An on-path blackbox network traffic security testing tool

A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10…