nicoSWD / asvs-checklist
OWASP Application Security Verification Standard 4.0 Checklist
☆32Updated 5 years ago
Alternatives and similar repositories for asvs-checklist:
Users that are interested in asvs-checklist are comparing it to the libraries listed below
- A colorful cross-platform python script to test misconfigurations of AWS S3 buckets both through authenticated and unauthenticated checks…☆39Updated 3 years ago
- Orchestron is an Application Vulnerability Management and Correlation Tool.Orchestron helps you solve one key problem "Find and fix vulne…☆31Updated 2 years ago
- Monitoring GitHub for sensitive data shared publicly☆66Updated 3 years ago
- A Burp plugin to export findings to DefectDojo☆30Updated last year
- Enhanced fork with logging, OpenAPI 3.0 and Python 3 for security monitoring workshops☆42Updated last year
- All-in-one tool for managing vulnerability reports from AppSec pipelines☆105Updated 2 years ago
- AWS Security Checks☆37Updated 7 years ago
- ☆23Updated 3 years ago
- retrive metadata endpoint data with these one liners.☆38Updated 4 years ago
- A simple script that generates an Excel friendly CSV file from an Amass JSON file.☆13Updated 2 years ago
- ☆22Updated 2 years ago
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider☆138Updated 3 years ago
- Security checks for http headers and cookies☆24Updated 4 years ago
- A collection of my Semgrep rules☆48Updated last year
- Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.☆77Updated 4 years ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆101Updated last year
- Assorted tools for security-related task for git repositories☆59Updated 2 years ago
- ☆35Updated 3 years ago
- Manual JavaScript Linting is a Bug☆49Updated 4 years ago
- Semgrep rules corresponding to the OWASP ASVS standard☆27Updated 4 years ago
- A very vulnerable implementation of a GraphQL API.☆59Updated 3 years ago
- CI Pipeline with Pixi, the WAF OWASP Core Rule Set and TestCafe tests.☆15Updated 3 years ago
- Easy-to-use Threat modeling-as-a-Code (TaaC) solution following DevSecOps principles. Simple CI/CD integration as well as console usage. …☆61Updated 8 months ago
- Appsecco training course content on Attacking and Auditing Dockers Containers and Kubernetes Clusters☆14Updated 4 years ago
- A small tool to help developers understand a huge set of security requirements from appsec teams☆45Updated 2 years ago
- Maturity Model Collaborative project☆14Updated 2 years ago
- GCP GOAT is the vulnerable application for learn the GCP Security☆63Updated last year
- Repo to hold the markdown-ified metadata on AppSec tools that are automation-friendly☆12Updated 8 years ago
- ☆122Updated last year
- ☆14Updated 2 years ago