
mimosa
Open-source web application security challenge platform with auto-approved registration, SQL dump generation, and Docker deployment for hands-on…

Open-source web application security challenge platform with auto-approved registration, SQL dump generation, and Docker deployment for hands-on…
High-performance network scanner for large-scale IP and port scanning with service identification, embedded device detection, and vulnerability…

This project is about creating and publishing threat model examples.

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

Burp Suite extension that finds exposed admin panels and login pages of web applications and infrastructure. 1,000+ payloads, OWASP WSTG-CONF-05.

Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite.

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

The Governed Agentic AI Operating System — Rust + Tauri 2.0 | 65 crates, 658 commands, 84 pages, 5,029 tests, 10/10 OWASP

Web application penetration testing lab — vulnerable Flask app, automated scanner, and professional pentest report. Covers OWASP Top 10, SQLi, XSS,…

OWASP Domain Protect - prevent subdomain takeover

In-depth attack surface mapping and asset discovery

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

End to End testing of Web, API, Cloud, Events and Security

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

CLI component of purpleteam

Application scanning component of purpleteam

Server scanning component of purpleteam