cytix-software / AppSec-Detection-Framework
A framework for understanding the capabilities of automated detection methods at identifying classes of application security vulnerabilities
☆14Updated this week
Alternatives and similar repositories for AppSec-Detection-Framework
Users that are interested in AppSec-Detection-Framework are comparing it to the libraries listed below
Sorting:
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.☆41Updated last year
- Maturity Model Collaborative project☆15Updated 2 years ago
- ☆35Updated 9 months ago
- ☆14Updated 2 years ago
- InfoSec OpenAI Examples☆19Updated last year
- Semgrep rules corresponding to the OWASP ASVS standard☆27Updated 4 years ago
- Additional active scan checks for BURP☆27Updated 7 months ago
- WAF bypass PoC☆47Updated last year
- ☆18Updated 3 years ago
- ☆47Updated 11 months ago
- ☆41Updated 2 months ago
- A small tool to help developers understand a huge set of security requirements from appsec teams☆45Updated 2 years ago
- ☆14Updated last year
- ☆110Updated last year
- 🧪 Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.☆39Updated 5 months ago
- Offensive Terraform module which creates Kali Linux from the AWS marketplace and installs cloud security tools (Pacu, Cloudsplaining, Sco…☆18Updated 4 years ago
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. …☆64Updated 10 months ago
- Protect against subdomain takeover☆92Updated 11 months ago
- A set of AWS resources for testing the Log4Shell vulnerability, deployable with terraform☆12Updated 3 years ago
- A web security research tool for DOM testing☆21Updated this week
- A Model Context Protocol server that connects AI assistants like Claude to AWS security services, allowing them to autonomously query, in…☆42Updated 2 weeks ago
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams☆105Updated 3 months ago
- Appsecco training course content on Attacking and Auditing Dockers Containers and Kubernetes Clusters☆14Updated 5 years ago
- POC tool to create signed AWS API GET requests to bypass Guard Duty alerting of off-instance credential use via SSRF☆58Updated last year
- CI Pipeline with Pixi, the WAF OWASP Core Rule Set and TestCafe tests.☆15Updated 3 years ago
- 📚A curated list of product security resources.☆19Updated 2 years ago
- An experimental project using LLM technology to generate security documentation for Open Source Software (OSS) projects☆28Updated 2 months ago
- Virtual Security Operations Center☆50Updated last year
- Build a CVE library with aggregated CISA, EPSS and CVSS data☆27Updated last year
- Example repository for GitHub Actions Time of Check to Time of Use (TOCTOU vulnerabilities)☆23Updated 2 weeks ago