PayloadsGit All the Payloads! A collection of web attack payloads.
Sast ScanScan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and Git friendly.
KicsFind security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
Zap HudThe OWASP ZAP Heads Up Display (HUD)
Sbt Dependency CheckSBT Plugin for OWASP DependencyCheck. Monitor your dependencies and report if there are any publicly known vulnerabilities (e.g. CVEs). 🌈
BlisqyVersion 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).
YawastYAWAST ...where a pentest starts. Security Toolkit for Web-based Applications
OvaaOversecured Vulnerable Android App
Web MethodologyMethodology for high-quality web application security testing - https://github.com/tprynn/web-methodology/wiki
Nist Data MirrorA simple Java command-line utility to mirror the CVE JSON data from NIST.
KurukshetraKurukshetra - A framework for teaching secure coding by means of interactive problem solving.
Njsscannjsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.
Oob ServerA Bind9 server for pentesters to use for Out-of-Band vulnerabilities
PidrilaPython Interactive Deepweb-oriented Rapid Intelligent Link Analyzer
SecurityratOWASP SecurityRAT (version 1.x) - Tool for handling security requirements in development
Bag Of HoldingAn application to assist in the organization and prioritization of software security activities.
BulwarkAn organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.
PurifyAll-in-one tool for managing vulnerability reports from AppSec pipelines
ReapsawReapsaw is a continuous security devsecops tool, which helps in enabling security into CI/CD Pipeline. It supports coverage for multiple programming languages.
SecuritySome of my security stuff and vulnerabilities. Nothing advanced. More to come.
Dependency TrackDependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
RailsgoatA vulnerable version of Rails that follows the OWASP Top 10
Kamus An open source, git-ops, zero-trust secret encryption and decryption solution for Kubernetes applications
Owasp VwadThe OWASP Vulnerable Web Applications Directory project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.
Juice ShopOWASP Juice Shop: Probably the most modern and sophisticated insecure web application
Www CommunityOWASP Community Pages are a place where OWASP can accept community contributions for security-related content.
Race The WebTests for race conditions in web applications. Includes a RESTful API to integrate into a continuous integration pipeline.
W3afw3af: web application attack and audit framework, the open source web vulnerability scanner.
Awesome Threat ModellingA curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.
CheatsheetseriesThe OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
Application Security Engineer Interview QuestionsSome of the questions which i was asked when i was giving interviews for Application/Product Security roles. I am sure this is not an exhaustive list but i felt these questions were important to be asked and some were challenging to answer
template-injection-workshopWorkshop on Template Injection (6 exercises) covering Twig, Jinja2, Tornado, Velocity and Freemaker engines.
JWTweakDetects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.
whoofWeb Browser Hooking Framework. Manage, execute and assess web browser vulnerabilities
vapivAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.
dependency-check-pluginJenkins plugin for OWASP Dependency-Check. Inspects project components for known vulnerabilities (e.g. CVEs).
threatmodel-sdkA Java library for parsing and programmatically using threat models
nerdbugFull Nuclei automation script with logic explanation.
edgeApplication-embedded connectivity and zero-trust components
appsec-educationPresentations, training modules, and other education materials from Duo Security's Application Security team.
awesome-policy-as-codeA curated list of policy-as-code resources like blogs, videos, and tools to practice on for learning Policy-as-Code.