Pinned Repositories
API-Security
OWASP API Security Project
ASVS
Application Security Verification Standard
CheatSheetSeries
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
DevGuide
The OWASP Developer Guide
Go-SCP
Golang Secure Coding Practices guide
mastg
The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.
masvs
The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
Nettacker
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
Top10
Official OWASP Top 10 Document Repository
wstg
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
OWASP's Repositories
OWASP/OWASP-Testing-Guide
OWASP Testing Guide
OWASP/WebGoat
This is a defunct code base. The project is located at: https://github.com/WebGoat
OWASP/OWASP-Proxy
Owasp Proxy
OWASP/Top-5-Machine-Learning-Risks
The OWASP Top 5 Machine Learning Risks[edit | edit source] The idea is to build the required resources which help software security community to understand the emerging technology of machine learning and how it is related to security, warn them about the risk associated with using ML, and discuss the defending techniques. Description[edit | edit source] Machine Learning has recently re-emerged as a powerful tool in multiple business sectors, especially when it is used for Predictive Analytics at the scale of Big Data. This technique becomes vital when it is harnessed for the Security services and applications like Fraud Detection, Anomaly Detection, Behavioral Analysis
OWASP/lapse-plus
LAPSE+ is a security scanner, based on the white box analysis of code for detecting vulnerabilities in Java EE Applications.
OWASP/AppSecEurope2017
OWASP/AppSec-Designer-Rule-Sets-for-Threat-Countermeasures-and-Security-Functional-Requirements
The most overtly detailed security blueprint you will ever need. Develop rule sets for use by Neo4j, AppSec Designer (TM), and any other tool choosing to use them, to define threat countermeasures and their related security functional component requirements.
OWASP/VirtualVillage
Owasp Virtual Village will provide users with access to numerous operating systems Desktop as well as Servers. They will be able to create custom apps for other owasp projects they will also be able to request test environments , or honey pots , etc.
OWASP/Maturity-Models-UI
UI for the Maturity-Models project
OWASP/Vicnum-BasicCTF
A rather basic (intentionally) vulnerable Web application written in PHP, part of the OWASP Vicnum Project
OWASP/Application-Security-Guide-For-CISOs-Project-v2
Among application security stakeholders, Chief Information Security Officers (CISOs),are responsible for application security from governance, compliance and risk perspectives. The Application Security Guide For CISOs seeks to help CISOs manage application security programs according to their own roles, responsibilities, perspectives and needs. Application security best practices and OWASP resources are referenced throughout the guide
OWASP/appsec-template
Jekyll web site template for OWASP AppSec conference web sites
OWASP/Cuiaba
OWASP Cuiaba, Brazil. A brilliant idea to have the entire chapter and their projects in github! Go Brazil!
OWASP/owasp-summit-2017-Outcomes
owasp summit 2017 Outcomes
OWASP/passfault-docker
Docker image base for OWASP passfault
OWASP/Threat-Modeling-Cheat-Sheets
OWASP/Threat-Modeling-Tools
OWASP/github-template
Templates recommended for GitHub repositories of OWASP projects
OWASP/Maturity-Models-API
Repo to hold the API backend files for the Maturity-Models project
OWASP/Maturity-Models-QA
Repo of QA files of BSIMM site (i.e. browser automation and performance tests)
OWASP/owasp-avatao
OWASP created challenges to run on the OpenSource Avatao engine
OWASP/passfault-docker-template
This is a template for customizing a passfault image with your own wordlists
OWASP/Threat-Model-Project
To be the source of all information threat model related including but not limited to cheat sheets, examples, new techniques and processes
OWASP/Threat-Modeling-Lightweight-Process
OWASP/A-D-Project
OWASP/AppSec-Israel-2017
OWASP/owasp-halifax
The OWASP Halifax Website
OWASP/owasp-summit-2017-site
Site pages for the owasp-summit-2017
OWASP/Vulnerability-Reporting-Project
OWASP/Threat-Modeling-Templates