cytix-software / AppSec-Detection-FrameworkLinks
A framework for understanding the capabilities of automated detection methods at identifying classes of application security vulnerabilities
β15Updated 2 weeks ago
Alternatives and similar repositories for AppSec-Detection-Framework
Users that are interested in AppSec-Detection-Framework are comparing it to the libraries listed below
Sorting:
- ποΈ STRIDE vs. ASVS equivalence tableβ76Updated 10 months ago
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. β¦β65Updated 3 weeks ago
- β111Updated 2 years ago
- A small tool to help developers understand a huge set of security requirements from appsec teamsβ46Updated 2 years ago
- β59Updated last month
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.β42Updated last year
- An experimental project using LLM technology to generate security documentation for Open Source Software (OSS) projectsβ31Updated 4 months ago
- InfoSec OpenAI Examplesβ19Updated last year
- AI featured threat modeling and security review actionβ44Updated 8 months ago
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagramsβ105Updated 5 months ago
- GCP GOAT is the vulnerable application for learn the GCP Securityβ64Updated last month
- A fun POC that is built to understand AI security agents.β31Updated 6 months ago
- π§ͺ Correlate Semgrep scans with Python test coverage to prioritize SAST findings and get bug fix suggestions via a self-hosted LLM.β39Updated 7 months ago
- Semgrep rules corresponding to the OWASP ASVS standardβ27Updated 4 years ago
- β41Updated 4 months ago
- A powerful tool that leverages AI to automatically generate comprehensive security documentation for your projectsβ89Updated 2 months ago
- AI featured threat modeling and security review projectβ16Updated 8 months ago
- β19Updated 3 years ago
- Maturity Model Collaborative projectβ15Updated 2 years ago
- A comprehensive checklist and guide for organizations looking to implement a robust cybersecurity programβ40Updated last week
- OWASP Foundation Web Respositoryβ9Updated 2 weeks ago
- GHAST (GitHub Actions Static Analysis Tool) is a tool to analyze the security posture of your GitHub Actions and its surrounding environmβ¦β20Updated last year
- Protect against subdomain takeoverβ92Updated last year
- β123Updated last year
- LLM Testing Findings Templatesβ72Updated last year
- β76Updated 5 months ago
- boostsecurityio/lotpβ128Updated 3 months ago
- code reviews to practiceβ16Updated 3 years ago
- A tool for scanning public or private AMIs for sensitive files and secrets. The tool follows the research made on AWS CloudQuarry where wβ¦β108Updated 8 months ago
- A simple script which implements different Cognito attacks such as Account Oracle or Priviledge Escalationβ107Updated last year