Checkmarx / capitalLinks
A built-to-be-vulnerable API application based on the OWASP top 10 API vulnerabilities. Use c{api}tal to learn, train and exploit API Security vulnerabilities within your own API Security CTF.
☆315Updated 4 months ago
Alternatives and similar repositories for capital
Users that are interested in capital are comparing it to the libraries listed below
Sorting:
- Websec interview questions by tib3rius answered☆307Updated 2 years ago
- A Broken Application - Very Vulnerable!☆180Updated this week
- ☆314Updated 5 months ago
- A curated list of Awesome Security Challenges.☆206Updated last year
- ☆195Updated 2 years ago
- GCPGoat : A Damn Vulnerable GCP Infrastructure☆424Updated last year
- Security Auditor Utility for GraphQL APIs☆581Updated last month
- BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for c…☆436Updated last month
- My personal collection of resources (mostly tools and training materials) for source code security audits.☆98Updated last year
- OWASP Code Review Guide Web Repository☆147Updated 3 years ago
- API Security Project aims to present unique attack & defense methods in API Security field☆287Updated 3 years ago
- Watch the latest awesome security talks around the globe☆277Updated 10 months ago
- APIsec|SCAN - Free API security testing using Github actions☆102Updated last year
- GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations☆337Updated 6 months ago
- Create your own vulnerable by design AWS penetration testing playground☆409Updated 4 months ago
- GraphQL automated security testing toolkit☆332Updated last year
- ☆348Updated 6 months ago
- Vulnerable code snippets with fixes for Web2, Web3, API, iOS, Android and Infrastructure-as-Code (IaC)☆165Updated last year
- This repo contains the code for my secure code review challenges. People used this as the primary resource to pass FAANG AppSec interview…☆288Updated last month
- Awesome information for WebSockets security research☆296Updated 3 years ago
- Docker toolbox for pentest of web based application.☆172Updated this week
- Find authentication (authn) and authorization (authz) security bugs in web application routes.☆280Updated 3 months ago
- Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files☆228Updated last month
- Create notes during a security code review in VSCode 📝 Import your favorite SAST tool findings 🛠️ and collaborate with others 🤝☆140Updated 2 months ago
- Security interview questions with possible explanation for roles in AppSec, Pentesting, Cloud Security, DevSecOps, Network Security and s…☆387Updated last year
- The AWS Enumerator was created for service enumeration and info dumping for investigations of penetration testers during Black-Box testin…☆240Updated 3 years ago
- A web CTF for training developers in bug hunting and secure coding!☆101Updated 11 months ago
- ☆86Updated 2 years ago
- This is a companion to the Security Engineer Questions☆204Updated 2 years ago
- AIGoat: A deliberately Vulnerable AI Infrastructure. Learn AI security through solving our challenges.☆260Updated 3 months ago