All Categories → Security → owasp

Top 122 owasp open source projects

Juice Shop Ctf
Capture-the-Flag (CTF) environment setup tools for OWASP Juice Shop
Insider
Static Application Security Testing (SAST) engine focused on covering the OWASP Top 10, to make source code analysis to find vulnerabilities right in the source code, focused on a agile and easy to implement software inside your DevOps pipeline. Support the following technologies: Java (Maven and Android), Kotlin (Android), Swift (iOS), .NET Full Framework, C#, and Javascript (Node.js).
Securecodingdojo
The Secure Coding Dojo is a platform for delivering secure coding training.
✭ 216
owasp
Wstg
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
Zap Hud
The OWASP ZAP Heads Up Display (HUD)
Fdsploit
File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.
Sbt Dependency Check
SBT Plugin for OWASP DependencyCheck. Monitor your dependencies and report if there are any publicly known vulnerabilities (e.g. CVEs). 🌈
Apicheck
The DevSecOps toolset for REST APIs
Securetea Project
The OWASP SecureTea Project provides a one-stop security solution for various devices (personal computers / servers / IoT devices)
Csrf Protector Php
CSRF Protector library: standalone library for CSRF mitigation
Zap Cli
A simple tool for interacting with OWASP ZAP from the commandline.
Python Honeypot
OWASP Honeypot, Automated Deception Framework.
Bluemonday
bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS
Phpvuln
Audit tool to find common vulnerabilities in PHP source code
Owasp Cloud Security
OWASP Cloud Security - Enabling conversations through threat and control stories
Owaspheaders.core
A .NET Core middleware for injecting the Owasp recommended HTTP Headers for increased security
Amass
In-depth Attack Surface Mapping and Asset Discovery
Go Agent
Sqreen's Application Security Management for the Go language
Owasp Orizon
Owasp Orizon is a source code static analyzer tool designed to spot security issues in Java applications.
Find Sec Bugs
The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
Securityrat
OWASP SecurityRAT (version 1.x) - Tool for handling security requirements in development
Pwning Juice Shop
GitBook markdown content for the eBook "Pwning OWASP Juice Shop"
Owtf
Offensive Web Testing Framework (OWTF), is a framework which tries to unite great tools and make pen testing more efficient http://owtf.org https://twitter.com/owtfp
Asvs
A simple web app that helps developers understand the ASVS requirements.
Themis
Easy to use cryptographic framework for data protection: secure messaging with forward secrecy and secure data storage. Has unified APIs across 14 platforms.
Mobile Security Framework Mobsf
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
Hacker ezines
A collection of electronic hacker magazines carefully curated over the years from multiple sources
Owasp Seraphimdroid
OWASP Seraphimdroid is an open source project with aim to create, as a community, an open platform for education and protection of Android users against privacy and security threats.
Breachdetector
Detect root, emulation, debug mode and other security concerns in your Xamarin apps
Threat Dragon
An open source, online threat modelling tool from OWASP
Threat Dragon Desktop
Desktop variant of OWASP Threat Dragon
✭ 53
cssowasp
Blackwidow
A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.
Awesome Ethical Hacking Resources
🔗 All the resources I could find for learning Ethical Hacking and Penetration Testing.
Owasp Zap Glue Ci Images
Ready to use images of Zap and Glue, especially for CI integration.
Threat Dragon Core
OWASP Threat Dragon core files
Dependency Track
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
Joomscan
OWASP Joomla Vulnerability Scanner Project
Opendoor
OWASP WEB Directory Scanner
Owasp Web Checklist
OWASP Web Application Security Testing Checklist
✭ 543
owasp
Zsc
OWASP ZSC - Shellcode/Obfuscate Code Generator
Owasp Vwad
The OWASP Vulnerable Web Applications Directory project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.
✭ 487
owaspappsec
Awesome Appsec
A curated list of resources for learning about application security
Dvna
Damn Vulnerable NodeJS Application
Glue
Application Security Automation
Www Community
OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.
Maryam
Maryam: Open-source Intelligence(OSINT) Framework
Dependency Check Sonar Plugin
Integrates Dependency-Check reports into SonarQube
1-60 of 122 owasp projects