Security-Knowledge-Framework / Labs
Monorepo of Labs for the Security Knowledge Framework (SKF)
☆36Updated this week
Alternatives and similar repositories for Labs:
Users that are interested in Labs are comparing it to the libraries listed below
- OWASP ASVS Security Evaluation Templates with Nuclei☆32Updated last week
- Prototype of Full Agentic Application Security Testing, FAAST = SAST + DAST + LLM agents☆43Updated last week
- This repository hosts several snippets and file related to the BsidesLV 2024 talk about Shadow and Zombie APIs by me☆18Updated 9 months ago
- Additional active scan checks for BURP☆27Updated 7 months ago
- ☆78Updated 2 years ago
- Nuclei plugins to audit Chrome extensions☆64Updated 9 months ago
- 📚A curated list of product security resources.☆19Updated 2 years ago
- Performing automated scan using Burp Suite Pro & Vmware Burp Rest API☆49Updated 2 years ago
- ☆71Updated last week
- CSPTPlayground is an open-source playground to find and exploit Client-Side Path Traversal (CSPT).☆117Updated last month
- GCP GOAT is the vulnerable application for learn the GCP Security☆64Updated last year
- Run Capture the Flags and Security Trainings with OWASP WrongSecrets☆46Updated last week
- InfoSec OpenAI Examples☆19Updated last year
- Damn Vulnerable SCA Application☆34Updated 2 weeks ago
- yataf extracts secrets and paths from files or urls - its best used against javascript files☆52Updated 8 months ago
- An extension to use Semgrep inside Burp Suite.☆88Updated last year
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams☆104Updated 3 months ago
- Regex patterns for manual application source code review☆27Updated 4 years ago
- A collection of Semgrep rules which followed security guidelines for .NET and Java.☆22Updated 3 years ago
- Blogpost series showcasing interesting cloud - web app security bugs☆47Updated last year
- This is vulnerable microservice written in many language to demonstrating OWASP API Top Security Risk (under development)☆43Updated 2 years ago
- Contains all my research and content produced regarding the log4shell vulnerability☆31Updated 3 years ago
- Semgrep rules corresponding to the OWASP ASVS standard☆27Updated 4 years ago
- My personal collection of resources (mostly tools and training materials) for source code security audits.☆78Updated 8 months ago
- Vulnerable environments paired with ready-to-use Nuclei templates for security testing and learning! 🚀☆89Updated last week
- The Arcanum Prompt Injection Taxonomy☆72Updated 3 weeks ago
- LLM Testing Findings Templates☆72Updated last year
- Community generated list of API security tests to find OWASP top10, HackerOne top 10 vulnerabilities☆36Updated 2 weeks ago
- Create your own recon & vulnerability scanner with Trickest and GitHub☆49Updated last year
- Sample Vulnerable and Secure Code Snippets for Various Vulnerabilities☆20Updated 10 months ago