
web-threat-mitigation
Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

Proof-of-concept for CVE-2024-48415: stored XSS vulnerability in itsourcecode Loan Management System v1.0 via borrower profile fields. Includes…

*This project is no longer maintained* OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and…

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

A program for testing WAF functionality

A collection of awesome resources related AI security

Flags parameters commonly associated with injection, SSRF, path traversal, IDOR, and SSTI, via passive Burp/ZAP scanning; also organizes manual…

Next-generation dependency vulnerability scanner with reachability analysis, SBOM generation, license audit, and container image scanning for CI/CD…

AzureGoat : A Damn Vulnerable Azure Infrastructure

Pen Test Report Generation and Assessment Collaboration

GCPGoat : A Damn Vulnerable GCP Infrastructure

A Security Tool for Enumerating WebSockets

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

Apache Real Time Logs Analyzer System

A structured knowledge base covering AI security fundamentals, threat modeling, red team offensive techniques, and blue team defenses, including LLM…

Advanced HTTP fingerprinting PoC

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

Public PoC Disclosure for CVE-2020-23839 - GetSimple CMS v3.3.16 suffers from a Reflected XSS on the Admin Login Portal