
wwwgrep
OWASP Foundation Web Respository

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

Apache Real Time Logs Analyzer System

Structured curriculum for learning application security, covering secure coding, threat modeling, and DevSecOps practices. Designed for self-paced…

🧮 An online calculator to assess the risk of web vulnerabilities based on OWASP Risk Assessment

AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

Automated CORS misconfiguration scanner that tests Origin header injection, wildcard reflection, and credential leakage across web applications and…

Burp Plugin to decrypt AES encrypted traffic on the fly

Penetration tests guide based on OWASP including test cases, resources and examples.

Public PoC Disclosure for CVE-2020-23839 - GetSimple CMS v3.3.16 suffers from a Reflected XSS on the Admin Login Portal

Automated authorization security scanner for OpenAPI-based APIs. Tests GET endpoints with multiple credential sets to detect privilege escalation and…

File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

A modern vulnerable web app

A documentation and tracking project with the goal of making package management systems more secure.

Academic purposes only. Attack against Salesforce lightning with guest privilege.

OWASP Passfault evaluates passwords and enforces password policy in a completely different way.

API-based scanner that retrieves and lists the latest Common Vulnerabilities and Exposures (CVEs) for automated security assessment and vulnerability…