OWASP / ASST
OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.
โ164Updated last month
Alternatives and similar repositories for ASST:
Users that are interested in ASST are comparing it to the libraries listed below
- ๐งฎ An online calculator to assess the risk of web vulnerabilities based on OWASP Risk Assessmentโ156Updated 3 years ago
- An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.โ179Updated last week
- VMC: a Scalable, Open Source and Free Vulnerability Management Platformโ88Updated last month
- OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessionsโ104Updated last year
- Static code analysis tool based on Elasticsearchโ129Updated 4 years ago
- A starter secure code review checklistโ181Updated 6 years ago
- The Pixi module is a MEAN Stack web app with wildly insecure APIs!โ120Updated 2 years ago
- Damn Vulnerable Java (EE) Applicationโ134Updated last year
- โ71Updated 4 years ago
- The OWASP DevSecOps Guideline explains how we can implement a secure pipeline and use best practices and introduce tools that we can use โฆโ62Updated 8 months ago
- OWASP Code Review Guide Web Repositoryโ129Updated 2 years ago
- Zed Attack Proxy Scripts for finding CVEs and Secrets.โ127Updated 2 years ago
- Software Component Verification Standard (SCVS)โ141Updated 10 months ago
- A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.โ55Updated 6 months ago
- Vulnerability Scan with Nucleiโ249Updated 3 months ago
- A tool geared towards pentesting APIs using OpenAPI definitions.โ174Updated 2 years ago
- Purposely vulnerable Java application to help lead secure coding workshopsโ178Updated 8 months ago
- Weaponizing Live CT logs for automated monitoring ofย assetsโ132Updated 3 years ago
- Enhanced fork with logging, OpenAPI 3.0 and Python 3 for security monitoring workshopsโ42Updated last year
- The Open Security Summit is focused on the collaboration between, Developers and Application Securityโ45Updated 2 months ago
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raiderโ138Updated 3 years ago
- Corsair_scan is a security tool to test Cross-Origin Resource Sharing (CORS).โ123Updated last year
- Monitor the internet attack surface of various public cloud environments. Currently supports AWS, GCP, Azure, DigitalOcean and Oracle Cloโฆโ124Updated 11 months ago
- Sample scan files for testing DefectDojo importsโ75Updated last month
- The DevSecOps toolset for REST APIsโ274Updated 2 years ago
- A deliberately vulnerable web application for learning web application security.โ124Updated last year
- The Secure Coding Frameworkโ268Updated 4 years ago
- Find cloud assets that no one wants exposed ๐ โ๏ธโ335Updated 4 years ago
- Zap baseline scanner in Docker with authenticationโ103Updated 9 months ago
- This repository contains an example Python API that is vulnerable to several different web API attacks.โ69Updated last year