Showing 36 of 73 projects
A comprehensive collection of payloads and bypass techniques for web application security testing and penetration testing.
A comprehensive collection of payloads and bypass techniques for web application security testing and penetration testing.
A comprehensive collection of security testing wordlists and payloads for penetration testers and security researchers.
A comprehensive checklist of security countermeasures for designing, testing, and releasing secure APIs.
An automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis, and security assessment framework.
A free, open-source web application security scanner for finding vulnerabilities during development and testing.
An advanced XSS detection suite that uses context analysis and intelligent payload generation to find vulnerabilities.
A curated collection of awesome software, libraries, books, and resources for cybersecurity professionals.
A curated collection of web security resources, tools, and research materials for learning penetration techniques.
A curated collection of ready-to-use .htaccess snippets for Apache web server configuration.
A penetration testing framework that exploits web browsers as beachheads for client-side attacks.
An open-source, next-generation Web Application Firewall (WAF) based on NGINX that makes web services secure by default.
An open-source, next-generation Web Application Firewall (WAF) that integrates as a reverse proxy to make web services secure by default.
A free, open-source WordPress security scanner for professionals and site maintainers to test website vulnerabilities.
A fast, simple, recursive content discovery tool written in Rust for forced browsing attacks.
A curated list of books, articles, websites, and tools for learning application security across multiple programming languages.
A curated list of resources for learning and practicing web application security, including tools, books, courses, and vulnerable labs.
A customizable HTTP/HTTPS proxy server library for Go, enabling request/response manipulation and MITM capabilities.
A modular web application fuzzer that replaces FUZZ keywords with payloads to test parameters, authentication, forms, and directories.
Exploits locked computers via USB to hijack internet traffic, steal browser cookies, and install persistent web backdoors using a Raspberry Pi Zero.
A community-curated collection of payloads, tools, and techniques for bug bounty hunters and security researchers.
A powerful web interface and WAF for Nginx/OpenResty, providing firewall, control panel, and real-time dashboards.
A tool for visual inspection of websites across many hosts, providing an overview of HTTP-based attack surfaces.
An automated penetration testing tool that detects and exploits command injection vulnerabilities in web applications.
A curated list of awesome information security courses, training resources, and hands-on labs for cybersecurity professionals and students.
A JavaScript library that sanitizes untrusted HTML to prevent XSS attacks using a configurable whitelist.
A native JavaScript implementation of TLS and a comprehensive cryptography toolkit for building secure web applications.
A curated collection of XSS resources including payloads, polyglots, bypass techniques, and tools for security researchers.
An open-source web application security scanner that identifies and exploits 200+ vulnerabilities for developers and penetration testers.
An unobtrusive Ruby authentication library for ActiveRecord-based Rails applications.
A Python script that discovers endpoints and their parameters in JavaScript files for penetration testing and bug hunting.
A comprehensive tutorial and example project for implementing JSON Web Token (JWT) authentication in web apps.
A modular authentication system for Go web applications, providing pluggable modules for common auth features.
A categorized collection of bug bounty write-ups organized by vulnerability type for security researchers.
A penetration testing tool that detects and exploits Server-Side Template Injection (SSTI) and code injection vulnerabilities.
A fast HTML sanitizer that cleans user-submitted HTML while preserving whitelisted elements and attributes.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.