
OWASP-MCP-Threat-Modeling
OWASP tool for systematic threat modeling using the Model Context Protocol to identify and mitigate security risks in software architecture.

OWASP tool for systematic threat modeling using the Model Context Protocol to identify and mitigate security risks in software architecture.

OWASP teaching modules covering application security fundamentals including risk management, secure software development, and operations security for…

OWASP hands-on Android security training lab with 78 MASVS/MASTG modules pairing vulnerable, secure, and attacker apps to demonstrate mobile…

OWASP Foundation Web Respository

OWASP Passfault evaluates passwords and enforces password policy in a completely different way.

Web and mobile application security training platform

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Perl-based Joomla CMS vulnerability scanner automating version enumeration, component detection, exploit matching, firewall identification, and…

Getting a handle on container security

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

This is a defunct code base. The project is located at: https://github.com/WebGoat

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Community-driven project providing guidance and resources to improve browser security, including best practices and educational materials for…

The Secure Coding Framework

Application Security Verification Standard

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

Golang Secure Coding Practices guide