OWASP-Benchmark / BenchmarkJava
OWASP Benchmark is a test suite designed to verify the speed and accuracy of software vulnerability detection tools. A fully runnable web app written in Java, it supports analysis by Static (SAST), Dynamic (DAST), and Runtime (IAST) tools that support Java. The idea is that since it is fully runnable and all the vulnerabilities are actually expl…
☆704Updated this week
Alternatives and similar repositories for BenchmarkJava:
Users that are interested in BenchmarkJava are comparing it to the libraries listed below
- The Web Application Vulnerability Scanner Evaluation Project☆233Updated 2 years ago
- Vulnerable Java based Web Application☆266Updated 10 months ago
- Semgrep Community Edition rules, maintained by Semgrep and the community. Free to use under the Semgrep Rules License.☆899Updated this week
- Evaluation Framework for Dependency Analysis (EFDA)☆43Updated 2 years ago
- Analyses your Java applications for open-source dependencies with known vulnerabilities, using both static analysis and testing to determ…☆541Updated last year
- Node application to help managing Maturity Models like the ones created by BSIMM and OpenSAMM☆193Updated 6 years ago
- GitHub Satellite 2020 workshops on finding security vulnerabilities with CodeQL for Java/JavaScript.☆210Updated 6 months ago
- NVD, Ubuntu, Alpine☆427Updated this week
- API Fuzzer which allows to fuzz request attributes using common pentesting techniques and lists vulnerabilities☆393Updated 7 years ago
- A byte code analyzer for finding deserialization gadget chains in Java applications☆1,029Updated 3 years ago
- SAMM stands for Software Assurance Maturity Model.☆398Updated 2 years ago
- Vulncode-DB project☆577Updated 3 years ago
- Fuzzapi is a tool used for REST API pentesting and uses API_Fuzzer gem☆654Updated 4 years ago
- Binaries for the CodeQL CLI☆810Updated 3 weeks ago
- Checkmarx Python SDK☆28Updated this week
- VisualCodeGrepper - Code security scanning tool.☆537Updated last year
- Global Security Database☆316Updated 11 months ago
- Software Component Verification Standard (SCVS)☆143Updated 3 weeks ago
- The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebas…☆142Updated last year
- Home page of project "KB"☆123Updated 3 weeks ago
- Generic SAST Library☆131Updated 5 months ago
- All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities☆783Updated 3 years ago
- A very vulnerable web site written in NodeJS with the purpose of have a project with identified vulnerabilities to test the quality of se…☆465Updated 8 months ago
- Burp/ZAP/Maven extension that integrate Retire.js repository to find vulnerable Javascript libraries.☆204Updated 10 months ago
- Purposely vulnerable Java application to help lead secure coding workshops☆179Updated 10 months ago
- REST/JSON API to the Burp Suite security tool.☆558Updated 11 months ago
- Yet Another Source Code Analyzer☆184Updated 3 years ago
- This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory☆880Updated 5 months ago
- Automate security tests using Burp Suite.☆226Updated 10 months ago
- AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.☆625Updated last year