BlazingWind / OWASP-ASVS-4.0-testing-guideLinks
โ123Updated last year
Alternatives and similar repositories for OWASP-ASVS-4.0-testing-guide
Users that are interested in OWASP-ASVS-4.0-testing-guide are comparing it to the libraries listed below
Sorting:
- ๐๏ธ STRIDE vs. ASVS equivalence tableโ76Updated 10 months ago
- The Security Champion Framework provides both a measuring stick and a roadmap generator for Champion Programs.โ108Updated last year
- A small tool to help developers understand a huge set of security requirements from appsec teamsโ45Updated 2 years ago
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.โ134Updated 5 years ago
- โ88Updated 3 years ago
- โ63Updated 2 years ago
- Segment's Threat Modeling training for our engineersโ243Updated 4 years ago
- drHEADer helps with the audit of security headers received in response to a single request or a list of requests.โ110Updated 5 months ago
- materials we hand outโ146Updated 2 months ago
- Semgrep rules corresponding to the OWASP ASVS standardโ27Updated 4 years ago
- A simple web app that helps developers understand the ASVS requirements.โ158Updated 3 months ago
- Presentations, training modules, and other education materials from Duo Security's Application Security team.โ74Updated 3 years ago
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. โฆโ65Updated 11 months ago
- โ35Updated 4 years ago
- ๐งฎ An online calculator to assess the risk of web vulnerabilities based on OWASP Risk Assessmentโ158Updated 3 years ago
- Orchestron is an Application Vulnerability Management and Correlation Tool.Orchestron helps you solve one key problem "Find and fix vulneโฆโ31Updated 2 years ago
- OWASP ASVS checklist for auditsโ205Updated last year
- A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for โฆโ19Updated last year
- Protect against subdomain takeoverโ92Updated last year
- โ111Updated 2 years ago
- The Pixi module is a MEAN Stack web app with wildly insecure APIs!โ126Updated 2 years ago
- A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestratโฆโ282Updated last week
- Ugly Duckling is a lightweight scanner built specifically for our Crowdsource community to submit proof-of-concept modulesโ189Updated 3 years ago
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raiderโ139Updated 3 years ago
- IAMFinder enumerates and finds users and IAM roles in a target AWS account.โ111Updated 4 years ago
- Find cloud assets that no one wants exposed ๐ โ๏ธโ345Updated 4 years ago
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagramsโ105Updated 4 months ago
- Node application to help managing Maturity Models like the ones created by BSIMM and OpenSAMMโ194Updated 6 years ago
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.โ172Updated 7 months ago
- Container Security Verification Standardโ58Updated 5 years ago