
CheatSheetSeries
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

A curated list of resources for learning about application security

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

The Web Application Hacker's Handbook - Extra Content

OWASP Vulnerable Web Application Project https://github.com/hummingbirdscyber

A curated list of awesome iOS application security resources.

Web application vulnerability scanner

Web application with vulnerabilities found in real cases, both in pentests and in Bug Bounty programs.

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

A guided mutation-based fuzzer for ML-based Web Application Firewalls

Static and dynamic Android application security analysis

Collaborative application security testing between humans and agents via CLI and MCP

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

Application Security Verification Standard