appsec

There are 389 repositories under appsec topic.

  • Application-Security

    Resources for Application Security including Web, API, Android, iOS and Thick Client

  • dd-trace-go

    dd-trace-go

    Datadog Go Library including APM tracing, profiling, and security monitoring.

    Language:Go652
  • Application-Security-Engineer-Interview-Questions

    Some of the questions which i was asked when i was giving interviews for Application/Product Security roles. I am sure this is not an exhaustive list but i felt these questions were important to be asked and some were challenging to answer

  • ovaa

    Oversecured Vulnerable Android App

    Language:Java633
  • Spoofy

    Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.

    Language:Python615
  • dependency-check-sonar-plugin

    Integrates Dependency-Check reports into SonarQube

    Language:Java590
  • race-the-web

    Tests for race conditions in web applications. Includes a RESTful API to integrate into a continuous integration pipeline.

    Language:Go585
  • rfi-lfi-payload-list

    🎯 RFI/LFI Payload List

  • privado

    Open Source Static Scanning tool to detect data flows in your code, find data security vulnerabilities & generate accurate Play Store Data Safety Report.

    Language:Dockerfile502
  • dd-trace-php

    Datadog PHP Clients

    Language:PHP487
  • badsecrets

    A library for detecting known secrets across many web frameworks

    Language:Python481
  • awesome-cicd-attacks

    Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.

  • threat-model-cookbook

    This project is about creating and publishing threat model examples.

    Language:Python404
  • njsscan

    njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.

    Language:JavaScript372
  • Blisqy

    Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

    Language:Python355
  • Free-RASP-Community

    SDK providing app protection and threat monitoring for mobile devices, available for Flutter, Cordova, Android and iOS.

  • agartha

    A Burp extension helps identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations, while also converting HTTP requests to JavaScript for enhanced XSS exploitation.

    Language:Python347
  • VulnerableApp

    OWASP VulnerableApp Project: For Security Enthusiasts by Security Enthusiasts.

    Language:Java290
  • casr

    Collect crash (or UndefinedBehaviorSanitizer error) reports, triage, and estimate severity.

    Language:Rust277
  • gram

    gram

    Gram is Klarna's own threat model diagramming tool

    Language:TypeScript270
  • sbt-dependency-check

    SBT Plugin for OWASP DependencyCheck. Monitor your dependencies and report if there are any publicly known vulnerabilities (e.g. CVEs). :rainbow:

    Language:Scala266
  • sechub

    SecHub provides a central API to test software with different security tools.

    Language:Java260
  • zap-hud

    The ZAP Heads Up Display (HUD)

    Language:Java250
  • PentestingEverything

    Penetration Testing For - Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting, etc...

    Language:JavaScript243
  • JavaSecurity

    Java web and command line applications demonstrating various security topics

    Language:Java235
  • nerdbug

    Full Nuclei automation script with logic explanation.

    Language:Shell232
  • domscan

    Simple tool to scan a website for (DOM-based) XSS vulnerabilities and Open Redirects.

    Language:JavaScript209
  • OversecuredVulnerableiOSApp

    Oversecured Vulnerable iOS App

    Language:Swift209
  • nist-data-mirror

    A simple Java command-line utility to mirror the CVE JSON data from NIST.

    Language:Java206
  • pidrila

    pidrila

    Python Interactive Deepweb-oriented Rapid Intelligent Link Analyzer

    Language:Python202
  • web-methodology

    Methodology for high-quality web application security testing - https://github.com/tprynn/web-methodology/wiki

  • grepmarx

    A source code static analysis platform for AppSec enthusiasts.

    Language:Python200
  • Session-Hijacking-Visual-Exploitation

    Session Hijacking Visual Exploitation

    Language:JavaScript189
  • OOB-Server

    A Bind9 server for pentesters to use for Out-of-Band vulnerabilities

    Language:Shell182
  • awesome-policy-as-code

    A curated list of policy-as-code resources like blogs, videos, and tools to practice on for learning Policy-as-Code.

  • bulwark

    bulwark

    An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

    Language:TypeScript180