Showing 36 of 38 projects
A free, open-source web application security scanner for finding vulnerabilities during development and testing.
Performs in-depth attack surface mapping and external asset discovery using open source intelligence and active reconnaissance.
Performs in-depth attack surface mapping and external asset discovery using open source intelligence and active reconnaissance.
A comprehensive manual for mobile app security testing and reverse engineering, aligned with OWASP MASVS and MASWE.
A curated list of books, articles, websites, and tools for learning application security across multiple programming languages.
A curated list of books, articles, websites, and tools for learning application security across multiple programming languages.
A curated list of resources for learning and practicing web application security, including tools, books, courses, and vulnerable labs.
A next-generation web scanner that identifies websites and their technologies using over 1800 plugins with configurable aggression levels.
An automated penetration testing tool that detects and exploits command injection vulnerabilities in web applications.
A curated collection of security conference talks and videos from events like DEF CON, Black Hat, and BSides.
A scanner that detects JavaScript libraries with known vulnerabilities and can generate a Software Bill of Materials (SBOM).
A fast, configurable HTML sanitizer for Go that scrubs user-generated content of XSS attacks using an allowlist policy.
An open-source, enterprise-grade Web Application Firewall library written in Go, compatible with ModSecurity SecLang rulesets.
An automated security testing framework for REST APIs that detects vulnerabilities like SQL injection, XSS, and CSRF.
A SpotBugs plugin for detecting security vulnerabilities in Java web and Android applications.
The OWASP Mobile Application Security Verification Standard (MASVS) is the industry standard for mobile app security.
A community-driven checklist of security precautions for Ruby on Rails applications to minimize vulnerabilities.
A curated list of threat modeling resources including books, courses, videos, tools, tutorials, and examples for learning and practicing threat modeling.
An OWASP training app with 62 challenges demonstrating real-world secrets management mistakes and how to find them.
An AI-powered tool that analyzes source code to discover every endpoint, exposing shadow APIs and mapping the complete attack surface for security testing.
An advanced Cross-Site Request Forgery (CSRF) audit and exploitation toolkit for security testing.
A security scanner that analyzes agentic AI workflows for vulnerabilities, visualizes their structure, and hardens system prompts.
A static code analyzer that detects security vulnerabilities in C# and VB.NET applications.
A small ASP.NET Core middleware package for adding and customizing security headers to protect websites.
A PHP library that sanitizes user input to prevent Cross-Site Scripting (XSS) attacks.
A comprehensive mobile application reverse engineering and analysis framework for security testing against OWASP mobile threats.
A free, open-source, cross-platform desktop application for threat modeling with system diagramming and automated threat generation.
A static application security testing (SAST) CLI tool that scans source code for OWASP Top 10 vulnerabilities across multiple programming languages.
Security libraries for ASP.NET applications that help implement HTTP security headers and other web security best practices.
An exhaustive security checklist for Node.js web services, focused on Express and Hapi frameworks.
An open-source Python framework for creating honeypots and honeynets to detect and analyze cyber attacks.
A CLI tool to export OWASP Juice Shop security challenges into CTFd, RootTheBox, or FBCTF compatible formats.
An ASP.NET Core middleware that injects OWASP-recommended HTTP security headers with a single line of code.
An AWS CDK construct to deploy, update, and stage Web Application Firewalls (WAFs) with central governance via AWS Firewall Manager.
A Flask app template with integrated SQLAlchemy, authentication, and Bootstrap frontend for building secure web applications.
A deliberately insecure OpenWrt-based firmware designed to teach IoT security testing through hands-on vulnerability challenges.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.