Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Appsec

Appsec

21 projects

Showing 21 of 21 projects

SQLMap
SQLMapPython

An open-source penetration testing tool that automates SQL injection detection and database takeover.

#security testing tool#python-tool#vulnerability-assessment
Stars38.0k
Forks6.3k
Last commit23 hours ago
Zap
ZapJava

A free, open-source web application security scanner for finding vulnerabilities during development and testing.

#hacktoberfest#owasp#web-security
Stars15.5k
Forks2.6k
Last commit1 day ago
Awesome Web Hacking
Awesome Web Hacking

A curated list of resources for learning and practicing web application security, including tools, books, courses, and vulnerable labs.

#hacking-tools#vulnerability-assessment#vulnerabilities
Stars7.2k
Forks1.4k
Last commit3 days ago
W3af
W3afPython

An open-source web application security scanner that identifies and exploits 200+ vulnerabilities for developers and penetration testers.

#sql-injection#web-security#cross-site-scripting
Stars4.9k
Forks1.2k
Last commit3 years ago
OpenZiti
OpenZitiGo

An open-source zero-trust networking platform that makes network services invisible to unauthorized users with cryptographic identity and end-to-end encryption.

#ztaa#zero-trust#vpn-2
Stars4.3k
Forks262
Last commit10 hours ago
Bearer
BearerGo

A static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.

#privacy-compliance#code-security#data-flow-analysis
Stars2.7k
Forks143
Last commit4 days ago
Bearer
BearerGo

Static application security testing (SAST) tool that scans source code to discover, filter, and prioritize security and privacy risks.

#privacy-compliance#code-security#data-flow-analysis
Stars2.7k
Forks143
Last commit4 days ago
KICS
KICSOpen Policy Agent

KICS is an open-source static analysis tool that finds security vulnerabilities, compliance issues, and misconfigurations in Infrastructure as Code.

#hacktoberfest#kubernetes#security-scanning
Stars2.7k
Forks377
Last commit1 day ago
cicd-goat
cicd-goatPython

A deliberately vulnerable CI/CD environment with 11 challenges to learn and practice CI/CD security.

#security-training#jenkins#devops
Stars2.3k
Forks414
Last commit2 years ago
Awesome Threat Modelling
Awesome Threat ModellingDockerfile

A curated list of threat modeling resources including books, courses, videos, tools, tutorials, and examples for learning and practicing threat modeling.

#owasp#awesome-list#risk-assessment
Stars1.8k
Forks307
Last commit2 years ago
open-appsec
open-appsecC++

A machine learning security engine that preemptively prevents web app and API threats using supervised and unsupervised models.

#owasp-top-10#self-hosted-security#zero-day-protection
Stars1.7k
Forks128
Last commit1 month ago
Secrets Patterns Database
Secrets Patterns DatabasePython

The largest open-source database of regex patterns for detecting secrets, API keys, passwords, and tokens in code.

#secret-detection#regex-patterns#regex
Stars1.6k
Forks189
Last commit11 months ago
Lonkero
LonkeroRust

A professional-grade web security scanner for penetration testing with intelligent, context-aware scanning and proof-based vulnerability detection.

#sql-injection#web-security#security-automation
Stars972
Forks80
Last commit1 day ago
android app security checklist
android app security checklist

A comprehensive checklist for designing, testing, and releasing secure Android applications based on OWASP standards.

#vulnerability-assessment#mobile-security#owasp-masvs
Stars895
Forks202
Last commit3 years ago
Oversecured Vulnerable Android App (OVAA)
Oversecured Vulnerable Android App (OVAA)Java

A vulnerable Android app aggregating known security vulnerabilities for testing and educational purposes.

#app-security#mobile-security#vulnerable-android-apps
Stars753
Forks201
Last commit2 years ago
CI/CD Attacks
CI/CD Attacks

A curated collection of offensive security research, techniques, and tools for attacking CI/CD pipelines and software supply chains.

#cicd#attack-techniques#red-teaming
Stars613
Forks58
Last commit1 month ago
GraphQLer
GraphQLerPython

A dependency-aware GraphQL API fuzzing tool that automatically generates and executes security tests based on schema introspection.

#api#graphql#api-testing-framework
Stars169
Forks16
Last commit1 day ago
Dependency Combobulator
Dependency CombobulatorPython

An open-source, modular framework to detect and prevent dependency confusion attacks across multiple package managers.

#supply-chain-security#secure-coding#python-tool
Stars95
Forks7
Last commit2 years ago
Application Security Education
Application Security EducationJavaScript

Open-source application security training materials including presentations and hands-on labs from Duo Security.

#developer-education#security-training#owasp-top-10
Stars77
Forks13
Last commit5 years ago
cdktg
cdktgTypeScript

AWS CDK constructs for defining threat models as code using the Threagile framework.

#threat#cdk#modeling
Stars13
Forks2
Last commit4 years ago
SecTester
SecTesterC#

Integrates Bright's DAST security scan engine directly into .NET unit tests to find vulnerabilities early.

#unit-testing#e2e#security
Stars3
Forks3
Last commit8 days ago

Related Tags

#Devsecops10#Security10#Penetration Testing7#Security Tools7#Automated Testing5#Api Security4#Vulnerability Detection4#Pentesting4#Vulnerability Scanner4#Docker4#Web Security4#Code Security3
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub