YaleUniversity / ZAP_ASVS_Checks
ZAP scripts to implement ASVS L1 checking
☆15Updated 2 years ago
Alternatives and similar repositories for ZAP_ASVS_Checks:
Users that are interested in ZAP_ASVS_Checks are comparing it to the libraries listed below
- Maturity Model Collaborative project☆14Updated last year
- Appsecco training course content on Attacking and Auditing Dockers Containers and Kubernetes Clusters☆14Updated 4 years ago
- Scripts that we use for pentesting☆42Updated 7 years ago
- CI Pipeline with Pixi, the WAF OWASP Core Rule Set and TestCafe tests.☆15Updated 3 years ago
- ☆23Updated 3 years ago
- OWASP Threat Dragon with Gitlab Integration☆25Updated 7 years ago
- Tools to automate AWS Cloud security assessments☆23Updated 4 years ago
- ☆10Updated 2 years ago
- AWS Security Checks☆36Updated 7 years ago
- Given a list of domains and known IP and buckets that are owned, which might be susceptible to domain hijacking?☆13Updated 4 months ago
- Updated incident response generator for training classes☆43Updated 3 years ago
- ZAP Management Scripts☆21Updated this week
- ☆38Updated 9 months ago
- A combined list of helpful awscli commands from Scott Piper's flaws.cloud exercise as well as from Beau Bullock's Breaching the Cloud Tra…☆19Updated 3 years ago
- Orchestron is an Application Vulnerability Management and Correlation Tool.Orchestron helps you solve one key problem "Find and fix vulne…☆31Updated 2 years ago
- OAuth Security Cheatsheet☆39Updated 10 years ago
- InfoSec OpenAI Examples☆19Updated last year
- ☆14Updated last year
- A tool to run nmap against each line in a script.☆17Updated 4 years ago
- Set of security tools that can be integrated in Jenkins pipelines.☆18Updated 5 years ago
- Semgrep rules corresponding to the OWASP ASVS standard☆27Updated 4 years ago
- Pivot into private VPC networks using a VPN connection☆41Updated 5 years ago
- ☆18Updated 3 years ago
- ☆18Updated 4 years ago
- A collection of slides, videos, and proof-of-concept scripts from various Rhino presentations.☆38Updated 6 years ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆14Updated 3 years ago
- A small library to alter AWS API requests; Used for fuzzing research☆22Updated last year
- CloudScraper: Tool to enumerate targets in search of cloud resources. S3 Buckets, Azure Blobs, Digital Ocean Storage Space.☆30Updated 2 years ago
- ☆14Updated 2 years ago
- Virtual Security Operations Center☆50Updated last year