Whitespots-OU / security-requirements-generatorLinks
A small tool to help developers understand a huge set of security requirements from appsec teams
โ47Updated 3 years ago
Alternatives and similar repositories for security-requirements-generator
Users that are interested in security-requirements-generator are comparing it to the libraries listed below
Sorting:
- ๐๏ธ equivalence table between OWASP ASVS standard and STRIDE threat modeling methodology.โ77Updated last year
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. โฆโ67Updated 5 months ago
- โ124Updated 2 years ago
- The Security Champion Framework provides both a measuring stick and a roadmap generator for Champion Programs.โ111Updated last year
- Semgrep rules corresponding to the OWASP ASVS standardโ27Updated 5 years ago
- โ69Updated 4 months ago
- โ88Updated 4 years ago
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.โ177Updated last year
- AI featured threat modeling and security review actionโ45Updated last year
- Presentations, training modules, and other education materials from Duo Security's Application Security team.โ77Updated 4 years ago
- drHEADer helps with the audit of security headers received in response to a single request or a list of requests.โ111Updated 10 months ago
- โ114Updated 2 years ago
- Segment's Threat Modeling training for our engineersโ245Updated 4 years ago
- materials we hand outโ148Updated 4 months ago
- ๐งฎ An online calculator to assess the risk of web vulnerabilities based on OWASP Risk Assessmentโ163Updated 4 years ago
- โ35Updated 4 years ago
- โ20Updated 3 years ago
- An extensive list of resources related to threat modelling. Gotta catch โem all!โ40Updated last week
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.โ134Updated 5 years ago
- Docs: Vulnerability management aggregation of AppSec & OpSec (Tools Listing)โ31Updated 2 years ago
- The Open Security Summit is focused on the collaboration between, Developers and Application Securityโ45Updated 4 months ago
- ๐งช Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.โ41Updated 11 months ago
- Purposely vulnerable Java application to help lead secure coding workshopsโ191Updated last year
- Holds the public Hacking the Cloud CTFs.โ60Updated last year
- The Pixi module is a MEAN Stack web app with wildly insecure APIs!โ134Updated 2 years ago
- Protect against subdomain takeoverโ94Updated 4 months ago
- InfoSec OpenAI Examplesโ19Updated 2 years ago
- Create notes during a security code review in VSCode ๐ Import your favorite SAST tool findings ๐ ๏ธ and collaborate with others ๐คโ140Updated last month
- KaiMonkey provides vulnerable infrastructure as code (IaC) to help explore and understand common cloud security threats exposed via IaC.โ105Updated last year
- โ33Updated 3 years ago