
goWAPT
Go Web Application Penetration Test

Go Web Application Penetration Test

An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

Some good resources for getting started with application security

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Extracts all possible endpoints, URLs, and paths from JavaScript files using customizable regex patterns for web application reconnaissance and API…

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

Deliberately vulnerable Node.js web application for practicing exploitation of SQL injection, XSS, IDOR, command injection, XXE, and deserialization…


CoWitness is a powerful web application testing tool that enhances the accuracy and efficiency of your testing efforts. It allows you to mimic an…

OWASP Thick Client Application Security Verification Standard

Web application that lets you test if your domain is vulnerable to email spoofing

Structured curriculum for learning application security, covering secure coding, threat modeling, and DevSecOps practices. Designed for self-paced…

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Just another vulnerable web application.

Proof-of-concept exploit for CVE-2023-6875, demonstrating a web application vulnerability. Includes code and instructions for reproducing the issue.

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…