
VulnReach
Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Source code for the Binaries of OWASP WrongSecrets

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

OWASP Secure Agent Playbook Project

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

pysap is an open source Python library that provides modules for crafting and sending packets using SAP's NI, Diag, Enqueue, Router, MS, SNC, IGS,…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Black-box XXE scanner detecting in-band, error-based, and blind out-of-band injection via statistical baselining, parser fingerprinting, and OOB…

Host and manage multiple Juice Shop instances for security trainings and Capture The Flags

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

Rust-powered HTTP Request Smuggling Scanner.

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…