Whitespots-OU / security-requirements-generator
A small tool to help developers understand a huge set of security requirements from appsec teams
โ45Updated 2 years ago
Alternatives and similar repositories for security-requirements-generator:
Users that are interested in security-requirements-generator are comparing it to the libraries listed below
- ๐๏ธ STRIDE vs. ASVS equivalence tableโ75Updated 5 months ago
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. โฆโ61Updated 7 months ago
- Semgrep rules corresponding to the OWASP ASVS standardโ27Updated 4 years ago
- The Security Champion Framework provides both a measuring stick and a roadmap generator for Champion Programs.โ107Updated last year
- โ122Updated last year
- โ109Updated last year
- InfoSec OpenAI Examplesโ19Updated last year
- โ63Updated 2 years ago
- The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.โ171Updated 2 months ago
- โ82Updated 3 years ago
- ๐งช Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.โ38Updated 2 months ago
- Create notes during a security code review in VSCode ๐ Import your favorite SAST tool findings ๐ ๏ธ and collaborate with others ๐คโ132Updated last year
- โ32Updated 2 years ago
- Orchestron is an Application Vulnerability Management and Correlation Tool.Orchestron helps you solve one key problem "Find and fix vulneโฆโ31Updated 2 years ago
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagramsโ101Updated 3 weeks ago
- โ91Updated this week
- โ36Updated 3 years ago
- A utility to (re-)import findings and language data into DefectDojoโ42Updated 4 months ago
- A Risk-Based Prioritization Taxonomy for prioritizing CVEs (Common Vulnerabilities and Exposures).โ71Updated 9 months ago
- ๐งฎ An online calculator to assess the risk of web vulnerabilities based on OWASP Risk Assessmentโ156Updated 3 years ago
- boostsecurityio/lotpโ112Updated this week
- โ33Updated 4 years ago
- Presentations, training modules, and other education materials from Duo Security's Application Security team.โ73Updated 3 years ago
- The Open Security Summit is focused on the collaboration between, Developers and Application Securityโ45Updated 2 months ago
- LLM Testing Findings Templatesโ66Updated last year
- Segment's Threat Modeling training for our engineersโ241Updated 3 years ago
- Protect against subdomain takeoverโ92Updated 8 months ago
- AI featured threat modeling and security review actionโ43Updated 3 months ago
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raiderโ138Updated 3 years ago
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.โ135Updated 4 years ago