
QRLJacking
Social engineering attack vector and exploitation framework for hijacking user sessions via QR code login, targeting web applications like WhatsApp,…

Social engineering attack vector and exploitation framework for hijacking user sessions via QR code login, targeting web applications like WhatsApp,…

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.


The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

pysap is an open source Python library that provides modules for crafting and sending packets using SAP's NI, Diag, Enqueue, Router, MS, SNC, IGS,…

PHP-RBAC is an authorization library for PHP. It provides developers with NIST Level 2 Standard Role Based Access Control and more, in the fastest…

Interactive platform linking security standards and guidelines for designing, developing, testing, and procuring secure software. Provides a unified…

Given JSON-like content, The JSON Sanitizer converts it to valid JSON.

Repo to hold mapping of user-security-stories

Project focused on governance and risk in application security, providing resources and frameworks for security maturity and risk management.

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

HoneySAP: SAP Low-interaction research honeypot

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

A documentation and tracking project with the goal of making package management systems more secure.

Structured playbook for integrating threat modeling into product security, covering stakeholder buy-in, organizational embedding, training, process…

Structured curriculum for learning application security, covering secure coding, threat modeling, and DevSecOps practices. Designed for self-paced…

Coordination structure for AI security standards and guidelines, reducing fragmentation and providing clear guidance for securing AI systems across…