All Categories → Security → application-security

Top 50 application-security open source projects

Juice Shop Ctf
Capture-the-Flag (CTF) environment setup tools for OWASP Juice Shop
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
Awesome Devsecops
Curating the best DevSecOps resources and tooling.
A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestration
An open source Android application that is intentionally vulnerable so as to act as a learning platform for Android application security beginners.
Web Methodology
Methodology for high-quality web application security testing -
Continuous Threat Modeling
A Continuous Threat Modeling methodology
XVWA is intentionally designed with many security flaws and enough technical ground to upskill application security knowledge. This whole idea is to evangelize web application security issues. Do let us know your suggestions for improvement or any more vulnerability you would like to see in XVWA future releases.
OWASP SecurityRAT (version 1.x) - Tool for handling security requirements in development
An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.
Mssqli Duet
SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing
VyAPI - A cloud based vulnerable hybrid Android App
A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis
Janusec Application Gateway, Provides Fast and Secure Application Delivery. JANUSEC应用网关,提供快速、安全的应用交付。
Breaking And Pwning Apps And Servers Aws Azure Training
Course content, lab setup instructions and documentation of our very popular Breaking and Pwning Apps and Servers on AWS and Azure hands on training!
Awesome Appsec
A curated list of resources for learning about application security
Secure Content Management for the Modern Web - "The sky is only the beginning"
Awesome Nginx Security
🔥 A curated list of awesome links related to application security related to the environments with NGINX or Kubernetes Ingres Controller (based on NGINX)
Grab N Run
Grab’n Run, a simple and effective Java Library for Android projects to secure dynamic code loading.
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
Application Security Engineer Interview Questions
Some of the questions which i was asked when i was giving interviews for Application/Product Security roles. I am sure this is not an exhaustive list but i felt these questions were important to be asked and some were challenging to answer
Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.
auth analyzer
Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.
Damn Vulnerable Bank is designed to be an intentionally vulnerable android application. This provides an interface to assess your android application security hacking skills.
Bucket Flaws ( S3 Bucket Mass Scanner ): A Simple Lightweight Script to Check for Common S3 Bucket Misconfigurations
The Open Security Summit 2020 is focused on the collaboration between, Developers and Application Security
Communicate with Fortify Software Security Center through REST API in java, a swagger generated client
1-50 of 50 application-security projects