BlazingWind / OWASP-ASVS-4.0-testing-guide
โ118Updated 10 months ago
Related projects: โ
- The Security Champion Framework provides both a measuring stick and a roadmap generator for Champion Programs.โ102Updated 8 months ago
- ๐๏ธ STRIDE vs. ASVS equivalence tableโ73Updated 3 weeks ago
- materials we hand outโ127Updated last week
- A small tool to help developers understand a huge set of security requirements from appsec teamsโ39Updated 2 years ago
- โ77Updated 3 years ago
- NextJS-based single-page application for completing and reviewing SAMM assessmentsโ67Updated last year
- A simple web app that helps developers understand the ASVS requirements.โ153Updated 6 months ago
- The Pixi module is a MEAN Stack web app with wildly insecure APIs!โ110Updated last year
- โ60Updated last year
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.โ132Updated 4 years ago
- Segment's Threat Modeling training for our engineersโ233Updated 3 years ago
- A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestratโฆโ271Updated last week
- โ30Updated 3 years ago
- drHEADer helps with the audit of security headers received in response to a single request or a list of requests.โ105Updated last week
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.โ165Updated 7 months ago
- Semgrep rules corresponding to the OWASP ASVS standardโ27Updated 3 years ago
- Presentations, training modules, and other education materials from Duo Security's Application Security team.โ68Updated 3 years ago
- ๐งฎ An online calculator to assess the risk of web vulnerabilities based on OWASP Risk Assessmentโ142Updated 3 years ago
- Container Security Verification Standardโ57Updated 5 years ago
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. โฆโ54Updated 2 months ago
- Find cloud assets that no one wants exposed ๐ โ๏ธโ330Updated 4 years ago
- โ222Updated 2 months ago
- Orchestron is an Application Vulnerability Management and Correlation Tool.Orchestron helps you solve one key problem "Find and fix vulneโฆโ31Updated last year
- OWASP Cloud Security - Enabling conversations through threat and control storiesโ175Updated 5 years ago
- โ36Updated 3 years ago
- IAMFinder enumerates and finds users and IAM roles in a target AWS account.โ107Updated 3 years ago
- โ108Updated last year
- Python API library for DefectDojoโ40Updated last year
- threatspec - continuous threat modeling, through codeโ327Updated 3 years ago
- A Docker container for remote penetration testing.โ132Updated 3 years ago